---
title: "CVE-2019-20372"
canonical: "https://kb.cynergy.app/space/MD/899252756/CVE-2019-20372"
format: markdown
---
**Description:**

NGINX before 1.17.7, with certain error_page configurations, allows HTTP request smuggling, as demonstrated by the ability of an attacker to read unauthorized web pages in environments where NGINX is being fronted by a load balancer.

**Published On:**

2020-01-09

**Updated On:**

2022-04-06

**Trending:**

FALSE

**CWE:**

CWE-444

**Mitigation:**

![image](media://61934750-a81a-4ad9-b118-40d90aed85d9)

Cynergy has an automated mitigation capability that requires integration with your WAF provider. 

Once integrated, you can request “Protect with WAF” 

This will move the exposed asset behind WAF protection

<span style="color: #97a0af">**Note: **</span><span style="color: #97a0af">Policies configuration should be defined separately </span>

**Remediation:**

Update based on the vendor recommendations:

|  |  |  |  |  |  |
| --- | --- | --- | --- | --- | --- |
| Patch Id | Vendor | Fix Title | Fix Description | Fix Published On | Fix URL |
| HT212818 | apple | Fixed in Xcode 13 | IDE Xcode Server<br />&nbsp; &nbsp; &nbsp; &nbsp; Impact: Multiple issues in nginx <br />&nbsp; &nbsp; &nbsp; &nbsp; Description: Multiple issues were addressed by updating nginx to version 1.21.0. <br />&nbsp; &nbsp; &nbsp; &nbsp; Available for: macOS Big Sur 11.3 and later <br />Installation note:<br>Xcode 13 may be obtained from:<br>[https://developer.apple.com/xcode/downloads/](https://developer.apple.com/xcode/downloads/)<br>To check that the Xcode has been updated:<br>- Select Xcode in the menu bar
- Select About Xcode
- The version after applying this update will be "Xcode 13".<br><br /> | 2022-02-20 | [https://support.apple.com/en-us/HT212818](https://support.apple.com/en-us/HT212818) |
| RHSA-2020:5495 | OpenSource | nginx-1.16.1-1.module+el8.3.0+8844+e5e7039f.1 | An update for the nginx:1.16 module is now available for Red Hat Enterprise Linux 8.<br>Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. | 2022-04-24 | [https://access.redhat.com/errata/RHSA-2020:5495](https://access.redhat.com/errata/RHSA-2020:5495) |
| MGASA-2020-0231 | mageia | Updated nginx packages fix security vulnerability | Nginx was updated due to the following vulnerabilities:  
ngx_http_special_response.c: With a certain error_page configuration,  
HTTP request smuggling is possible. Thus, an attacker may be able to  
read unauthorized web pages at times when NGINX is being fronted by a  
load balancer. (CVE-2019-20372). | 2020-05-28 | [http://advisories.mageia.org/MGASA-2020-0231.html](http://advisories.mageia.org/MGASA-2020-0231.html) |
| openSUSE-SU-2020:0204-1 | suse | Security update for nginx | This update for nginx fixes the following issues:<br>- CVE-2019-20372: Fixed an HTTP request smuggling with certain error_page<br>configurations which could have allowed unauthorized web page reads (bsc#1160682).<br>This update was imported from the SUSE:SLE-15-SP1:Update update project. | 2020-02-13 | [http://lists.opensuse.org/opensuse-security-announce/2020-02/msg00013.html](http://lists.opensuse.org/opensuse-security-announce/2020-02/msg00013.html) |
| RHSA-2020:2817 | redhat | Red Hat Security Advisory: rh-nginx116-nginx security update | An update for rh-nginx116-nginx is now available for Red Hat Software Collections.<br>Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. | 2020-07-03 | [https://access.redhat.com/errata/RHSA-2020:2817](https://access.redhat.com/errata/RHSA-2020:2817) |
| RHSA-2020:5495 | redhat | Red Hat Security Advisory: nginx:1.16 security update | An update for the nginx:1.16 module is now available for Red Hat Enterprise Linux 8.<br>Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. | 2020-12-19 | [https://access.redhat.com/errata/RHSA-2020:5495](https://access.redhat.com/errata/RHSA-2020:5495) |
| RHSA-2021:0778 | redhat | Red Hat Security Advisory: Red Hat Ansible Tower 3.6.7-1 - Container security and bug fix update | Red Hat Ansible Tower 3.6.7-1 - RHEL7 Container<br>Red Hat Product Security has rated this update as having a security impact of  
Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. | 2021-03-10 | [https://access.redhat.com/errata/RHSA-2021:0778](https://access.redhat.com/errata/RHSA-2021:0778) |
| RHSA-2021:0779 | redhat | Red Hat Security Advisory: Red Hat Ansible Tower 3.7.5-1 - Container security and bug fix update | Red Hat Ansible Tower 3.7.5-1 - RHEL7 Container<br>Red Hat Product Security has rated this update as having a security impact of  
Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. | 2021-03-10 | [https://access.redhat.com/errata/RHSA-2021:0779](https://access.redhat.com/errata/RHSA-2021:0779) |
| APPLE-SA-2021-09-20-4 | apple | APPLE-SA-2021-09-20-4 Xcode 13 |  | 2021-09-21 | [https://lists.apple.com/archives/security-announce/2021/Sep/msg00008.html](https://lists.apple.com/archives/security-announce/2021/Sep/msg00008.html) |
| openSUSE-SU-2020:0204-1 | suse | Security update for nginx | This update for nginx fixes the following issues:<br>- CVE-2019-20372: Fixed an HTTP request smuggling with certain error_page<br>configurations which could have allowed unauthorized web page reads (bsc#1160682).<br>This update was imported from the SUSE:SLE-15-SP1:Update update project. | 2021-04-16 | [https://lists.opensuse.org/opensuse-security-announce/2020-02/msg00013.html](https://lists.opensuse.org/opensuse-security-announce/2020-02/msg00013.html) |
| usn-4235-1 | canonical | nginx vulnerability | Bert JW Regeer and Francisco Oca Gonzalez discovered that nginx incorrectly  
handled certain error_page configurations. A remote attacker could possibly  
use this issue to perform HTTP request smuggling attacks and access  
resources contrary to expectations. | 2020-07-29 | [https://ubuntu.com/security/notices/USN-4235-1](https://ubuntu.com/security/notices/USN-4235-1) |
| usn-4235-2 | canonical | nginx vulnerability | USN-4235-1 fixed a vulnerability in nginx. This update provides  
the corresponding update for Ubuntu 14.04 ESM.  
Original advisory details:  
Bert JW Regeer and Francisco Oca Gonzalez discovered that nginx incorrectly  
 handled certain error_page configurations. A remote attacker could possibly  
 use this issue to perform HTTP request smuggling attacks and access  
 resources contrary to expectations. | 2020-07-29 | [https://ubuntu.com/security/notices/USN-4235-2](https://ubuntu.com/security/notices/USN-4235-2) |
| SUSE-SU-2020:0348-1 | suse | Security update for nginx | This update for nginx fixes the following issues:<br>- CVE-2019-20372: Fixed an HTTP request smuggling with certain error_page<br>configurations which could have allowed unauthorized web page reads (bsc#1160682). | 2020-02-08 | [https://www.suse.com/support/update/announcement/2020/suse-su-20200348-1/](https://www.suse.com/support/update/announcement/2020/suse-su-20200348-1/) |
| SUSE-SU-2020:1171-1 | suse | Security update for nginx | This update for nginx fixes the following issues:<br>nginx was updated to 1.16.1 (jsc#ECO-1401)<br>- Added TLS 1.3 support (jsc#SLE-9295, bsc#1150711)
- Replaced obsolete GeoIP module with MaxMinDB-based GeoIP2<br>(jsc#SLE-11184, bsc#1156202)<br>- Started nginx after network is online (bsc#1155690)
- CVE-2019-20372: Fixed an HTTP request smuggling with certain error_page<br>configurations which could have allowed unauthorized web page reads (bsc#1160682). | 2020-05-06 | [https://www.suse.com/support/update/announcement/2020/suse-su-20201171-1/](https://www.suse.com/support/update/announcement/2020/suse-su-20201171-1/) |