Bug 892030 (CVE-2011-4968) - CVE-2011-4968 nginx: http proxy module does not validate SSL certificates
Summary: CVE-2011-4968 nginx: http proxy module does not validate SSL certificates
Alias: CVE-2011-4968
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
Depends On: 892032 892033
TreeView+ depends on / blocked
Reported: 2013-01-04 21:56 UTC by Vincent Danen
Modified: 2019-09-29 12:58 UTC (History)
5 users (show)

Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Clone Of:
Last Closed: 2019-06-10 10:59:51 UTC

Attachments (Terms of Use)

Description Vincent Danen 2013-01-04 21:56:11 UTC
It was reported [1],[2] that nginx does not verify the identity of an origin server when the http proxy module talks to that origin server over HTTPS.  This could allow for a MITM attack between the proxy and the origin server.

There are proposed patches attached to the upstream ticket, but as of yet this is not fixed in any release.

[1] http://www.openwall.com/lists/oss-security/2013/01/03/4
[2] http://trac.nginx.org/nginx/ticket/13

Comment 1 Vincent Danen 2013-01-04 21:58:06 UTC
Created nginx tracking bugs for this issue

Affects: epel-all [bug 892032]
Affects: fedora-all [bug 892033]

Comment 2 Jamie Nguyen 2013-06-27 13:39:58 UTC
Upstream apparently do not consider this important enough to fix. Since the upstream bug was originally reported 2 yeas ago, closing as WONTFIX for now until upstream decide they want to patch it.

Comment 4 Product Security DevOps Team 2019-06-10 10:59:51 UTC
This CVE Bugzilla entry is for community support informational purposes only as it does not affect a package in a commercially supported Red Hat product. Refer to the dependent bugs for status of those individual community products.

Note You need to log in before you can comment on or make changes to this bug.