CVE Tools

CVE-2018-9230

Public exploit available. Not confirmed exploited in the wild yet. A vendor fix is available.

Published Updated Sources: CVE.org, NVD

What to do

The vendor has published a fix. Version details are below where the sources state them.

Steps

Written by AI from the record
  1. Check your OpenResty version and confirm whether you use ngx.req.get_uri_args or ngx.req.get_post_args in your Lua apps or routing logic.
  2. If your version is OpenResty through 1.13.6.1, plan an upgrade to a version where it is fixed.
  3. Upgrade OpenResty to the fixed release (fixed in 1.13.6.1 per vendor).
  4. If you rely on a WAF/X-WAF that inspects request parameters, test with requests that include more than 100 parameters and verify protections still trigger.

What it is

From the CVE record

In OpenResty through 1.13.6.1, URI parameters are obtained using the ngx.req.get_uri_args and ngx.req.get_post_args functions that ignore parameters beyond the hundredth one, which might allow remote attackers to bypass intended access restrictions or interfere with certain Web Application Firewall (ngx_lua_waf or X-WAF) products. NOTE: the vendor has reported that 100 parameters is an intentional default setting, but is adjustable within the API. The vendor's position is that a security-relevant misuse of the API by a WAF product is a vulnerability in the WAF product, not a vulnerability in OpenResty

In plain language

Written by AI from the record

OpenResty through 1.13.6.1 can mishandle very large numbers of request parameters, which may let attackers bypass some protections; most small businesses should patch if they use OpenResty in front of public web traffic.

CVE-2018-9230 is an issue in OpenResty (through 1.13.6.1) where ngx.req.get_uri_args / ngx.req.get_post_args ignore parameters after the 100th, which can allow crafted requests to bypass or interfere with access-control or WAF logic that depends on those parameters; public proof-of-concept exists, but it’s not confirmed via CISA KEV.

If you're affected

  • Bypass web access restrictions
  • WAF protection interference
  • Potential data exposure
  • Service disruption risk

Exploitation

Where each signal puts this CVE on the scale from published to confirmed exploited.

EPSS96th
Public exploit
CISA KEV

Not in the catalog. CISA has not confirmed exploitation.

Public exploits

1 source with a proof of concept or module.

Exploit links, PoCs and Metasploit modules after sign-in
EPSS

13% chance of exploitation activity in the next 30 days, which ranks it in the 96th percentile of scored CVEs.

Exploit Prediction Scoring System, FIRST.org. A probability, not a confirmation.

Attention now

Rising.

Lifecycle

The patch came 471 days before any public exploit.

  1. EPSS band changelow → moderateepss band change
  2. EPSS band changemoderate → lowepss band change
  3. EPSS band changelow → moderateepss band change
  4. EPSS band changemoderate → lowepss band change
  5. EPSS band change0 → moderateepss band change
  6. EPSS band changemoderate → 0epss band change

Affected products

And 1 more affected product. See all after sign-in

Technical detail

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Scored 9.8 by NVD.

How it is reached

  • Attack Vector NetworkExploitable remotely over the network without any special conditions
  • Attack Complexity LowNo special conditions — the attack can be reliably reproduced
  • Privileges Required NoneNo authentication required — anyone can exploit this
  • User Interaction NoneNo user interaction needed — fully automated exploitation

Scope

  • Scope UnchangedImpact is limited to the vulnerable component itself

Impact if exploited

  • Confidentiality HighTotal information disclosure — all data in the component is compromised
  • Integrity HighTotal loss of integrity — attacker can modify any data in the component
  • Availability HighTotal denial of service — the component is completely unavailable

Weaknesses

ATT&CK techniques

Mapped from the weaknesses above (CWE to ATT&CK), not observed in attacks.

Sources

Watch the software you run.

My Stack ranks new CVEs for your products by real-world exploitation, so the next serious one reaches you without reading every advisory.

We'll flag the next CVE, public exploit or patch for Openresty, not every advisory. This one: public exploit.

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store