CVE-2013-4547 describes a security bypass vulnerability in Nginx versions 0.8.41 through 1.4.3 and 1.5.x before 1.5.7, affecting products like F5, openSUSE, and SUSE. This flaw allows remote attackers to circumvent intended restrictions by including an unescaped space character in a URI. With a CVSS score of 7.5, this vulnerability is considered highly severe, allowing for potential compromise of confidentiality, integrity, and availability with low attack complexity and no authentication required. While not listed in CISA's KEV catalog, an ExploitDB entry (EDB-38846) exists, and it has garnered significant community discussion and media coverage, indicating awareness and potential for exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0.8.41, < 1.4.4CPE matchmatch criteria | cpe:2.3:a:f5:nginx:*:*:*:*:*:*:*:* | ||
>= 1.5.0, <= 1.5.6CPE matchmatch criteria | cpe:2.3:a:f5:nginx:*:*:*:*:*:*:*:* | ||
1.3CPE matchmatch criteria | cpe:2.3:a:suse:lifecycle_management_server:1.3:*:*:*:*:*:*:* | ||
1.3CPE matchmatch criteria | cpe:2.3:a:suse:studio_onsite:1.3:*:*:*:*:*:*:* | ||
1.3CPE matchmatch criteria | cpe:2.3:a:suse:webyast:1.3:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:P/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Request line parsing vulnerability
Jan 1, 2013Request line parsing vulnerability
Jan 1, 2013Request line parsing vulnerability
Jan 1, 2013Request line parsing vulnerability
Jan 1, 2013Request line parsing vulnerability
Jan 1, 2013Request line parsing vulnerability
Request line parsing vulnerability
Patch nginx for CVE-2013-4547
Request line parsing vulnerability