Skip to main content
CRITICAL

CVE-2018-9230

CVSS v3

9.8

CRITICAL

EPSS Score

42.7 %

exploit probability

CISA KEV

No

known exploited

Exploitation

SSVC status

Description

In OpenResty through 1.13.6.1, URI parameters are obtained using the ngx.req.get_uri_args and ngx.req.get_post_args functions that ignore parameters beyond the hundredth one, which might allow remote attackers to bypass intended access restrictions or interfere with certain Web Application Firewall (ngx_lua_waf or X-WAF) products. NOTE: the vendor has reported that 100 parameters is an intentional default setting, but is adjustable within the API. The vendor's position is that a security-relevant misuse of the API by a WAF product is a vulnerability in the WAF product, not a vulnerability in OpenResty

Technical details

Published
2018-04-02

Frequently asked questions

What is CVE-2018-9230?

In OpenResty through 1.13.6.1, URI parameters are obtained using the ngx.req.get_uri_args and ngx.req.get_post_args functions that ignore parameters beyond the hundredth one, which might allow remote attackers to bypass intended access restrictions or interfere with certain Web Application Firewall (ngx_lua_waf or X-WAF) products. NOTE: the vendor has reported that 100 parameters is an intentional default setting, but is adjustable within the API. The vendor's position is that a security-relevant misuse of the API by a WAF product is a vulnerability in the WAF product, not a vulnerability in OpenResty

Is CVE-2018-9230 actively exploited?

Active exploitation of CVE-2018-9230 has not been confirmed. The EPSS score is 42.7%, indicating the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2018-9230?

CVE-2018-9230 has a CVSS v3 base score of 9.8 (CRITICAL severity).

Is CVE-2018-9230 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.

No credit card required · 500 free checks/month · Free API key