nginx vulnerability

Frank Liu gfrankliu at gmail.com
Thu Nov 19 22:06:46 UTC 2020


Hi,

CVE-2019-20372 mentioned a security vulnerability, but I don't see it in
http://nginx.org/en/security_advisories.html
Does that mean CVE-2019-20372 is not considered a security vulnerability by
nginx? Or is it because nginx standard config won't be vulnerable, and
users have to enable error_log in order to be vulnerable?

Thanks!
Frank
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://mailman.nginx.org/pipermail/nginx/attachments/20201119/6bc8e234/attachment.htm>


More information about the nginx mailing list