CVE-2020-36309
Dashboard / Vulnerabilities / CVE-2020-36309
Summary:
Details: ngx_http_lua_module (aka lua-nginx-module) before 0.10.16 in OpenResty allows unsafe characters in an argument when using the API to mutate a URI, or a request or response header.
References: https://lists.debian.org/debian-lts-announce/2025/06/msg00026.html, https://news.ycombinator.com/item?id=26712562, https://security.netapp.com/advisory/ntap-20210507-0005/, https://github.com/openresty/lua-nginx-module/compare/v0.10.15...v0.10.16, https://github.com/openresty/lua-nginx-module/pull/1654
Affected packages
Package
Name:
Purl:
Affected ranges
Affected versions
v0.10.16rc5
v0.10.16rc4
v0.10.16rc3
v0.10.16rc2
v0.10.16rc1
v0.10.15
v0.10.15rc1
v0.10.14
v0.10.14rc7
v0.10.14rc6
v0.10.14rc5
v0.10.14rc4
v0.10.14rc3
v0.10.14rc2
v0.10.14rc1
v0.10.13
v0.10.13rc1
v0.10.12
v0.10.12rc2
v0.10.12rc1
v0.10.11
v0.10.11rc3
v0.10.11rc2
v0.10.11rc1
v0.10.10
v0.10.9
v0.10.9rc9
v0.10.9rc8
v0.10.9rc7
v0.10.9rc6
v0.10.9rc5
v0.10.9rc4
v0.10.9rc3
v0.10.9rc2
v0.10.9rc1
v0.10.8
v0.10.7
v0.10.6
v0.10.6rc2
v0.10.6rc1
v0.10.5
v0.10.4
v0.10.4rc1
v0.10.3
v0.10.2
v0.10.1
v0.10.1rc1
v0.10.1rc0
v0.10.0
v0.10.0rc0
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
