CVE-2024-24990
NGINX vulnerability analysis and mitigation

Overview

CVE-2024-24990 is a security vulnerability affecting NGINX Plus and NGINX OSS when configured to use the HTTP/3 QUIC module. The vulnerability was disclosed on February 14, 2024, and affects NGINX versions 1.25.0 through 1.25.3. The HTTP/3 QUIC module, which is not enabled by default and is considered experimental, can be exploited through undisclosed requests that cause NGINX worker processes to terminate (NVD, OSS Security).

Technical details

The vulnerability has been assigned a CVSS v3.1 base score of 7.5 (HIGH) with the vector string CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H. It is classified as a Use After Free (CWE-416) vulnerability. The issue specifically affects installations where NGINX has been explicitly compiled with the ngxhttpv3_module and the 'quic' option is enabled in the 'listen' directive within the configuration file (NVD).

Impact

When exploited, this vulnerability allows remote unauthenticated attackers to cause denial-of-service (DoS) conditions by triggering worker process crashes. The vulnerability may also have potential for further impact beyond simple crashes, though the exact scope remains under investigation (Security Online).

Mitigation and workarounds

The vulnerability has been patched in NGINX version 1.25.4. Organizations running affected versions should upgrade immediately to this version or later. For those unable to upgrade immediately, the only reliable mitigation is to disable HTTP/3 functionality, as no other workarounds are available (Security Online).

Additional resources


SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management