NGINX Plus and NGINX Open Source have a vulnerability in the ngx_stream_ssl_module module due to the improper handling of revoked certificates when configured with the ssl_verify_client on and ssl_ocsp on directives, allowing the TLS handshake to succeed even after an OCSP check identifies the certificate as revoked.
Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Nginx_plus | F5 | r33 (including) | r33 (including) |
| Nginx_plus | F5 | r33-p1 (including) | r33-p1 (including) |
| Nginx_plus | F5 | r33-p2 (including) | r33-p2 (including) |
| Nginx_plus | F5 | r33-p3 (including) | r33-p3 (including) |
| Nginx_plus | F5 | r34 (including) | r34 (including) |
| Nginx_plus | F5 | r34-p1 (including) | r34-p1 (including) |
| Nginx_plus | F5 | r34-p2 (including) | r34-p2 (including) |
| Nginx_plus | F5 | r35-p1 (including) | r35-p1 (including) |
| Nginx_plus | F5 | r36 (including) | r36 (including) |
| Nginx_plus | F5 | r36-p1 (including) | r36-p1 (including) |
| Nginx_plus | F5 | r36-p2 (including) | r36-p2 (including) |
| Red Hat Hardened Images | RedHat | nginx-main-1.30.0-1.hum1 | * |
| Nginx | Ubuntu | noble | * |
| Nginx | Ubuntu | questing | * |
| Nginx | Ubuntu | upstream | * |