CVSS v3
9.8
CRITICAL
EPSS Score
42.7 %
exploit probability
CISA KEV
No
known exploited
Exploitation
—
SSVC status
Description
In OpenResty through 1.13.6.1, URI parameters are obtained using the ngx.req.get_uri_args and ngx.req.get_post_args functions that ignore parameters beyond the hundredth one, which might allow remote attackers to bypass intended access restrictions or interfere with certain Web Application Firewall (ngx_lua_waf or X-WAF) products. NOTE: the vendor has reported that 100 parameters is an intentional default setting, but is adjustable within the API. The vendor's position is that a security-relevant misuse of the API by a WAF product is a vulnerability in the WAF product, not a vulnerability in OpenResty
Technical details
- Published
- 2018-04-02
Frequently asked questions
What is CVE-2018-9230?
In OpenResty through 1.13.6.1, URI parameters are obtained using the ngx.req.get_uri_args and ngx.req.get_post_args functions that ignore parameters beyond the hundredth one, which might allow remote attackers to bypass intended access restrictions or interfere with certain Web Application Firewall (ngx_lua_waf or X-WAF) products. NOTE: the vendor has reported that 100 parameters is an intentional default setting, but is adjustable within the API. The vendor's position is that a security-relevant misuse of the API by a WAF product is a vulnerability in the WAF product, not a vulnerability in OpenResty
Is CVE-2018-9230 actively exploited?
Active exploitation of CVE-2018-9230 has not been confirmed. The EPSS score is 42.7%, indicating the estimated probability of exploitation in the next 30 days.
What is the CVSS score for CVE-2018-9230?
CVE-2018-9230 has a CVSS v3 base score of 9.8 (CRITICAL severity).
Is CVE-2018-9230 affecting your environment?
Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.
No credit card required · 500 free checks/month · Free API key
Other 2018 vulnerabilities worth triaging
Ranked by exploit probability (EPSS).