Medium severity4.3NVD Advisory· Published Feb 5, 2025· Updated Jun 17, 2026
CVE-2025-23419
CVE-2025-23419
Description
When multiple server blocks are configured to share the same IP address and port, an attacker can use session resumption to bypass client certificate authentication requirements on these servers. This vulnerability arises when TLS Session Tickets https://nginx.org/en/docs/http/ngx_http_ssl_module.html#ssl_session_ticket_key are used and/or the SSL session cache https://nginx.org/en/docs/http/ngx_http_ssl_module.html#ssl_session_cache are used in the default server and the default server is performing client certificate authentication.
Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
15- osv-coords12 versionspkg:apk/chainguard/ingress-nginx-controller-1.13pkg:apk/chainguard/ingress-nginx-controller-1.14pkg:apk/chainguard/ingress-nginx-controller-1.15pkg:apk/chainguard/ingress-nginx-controller-fips-1.13pkg:apk/chainguard/ingress-nginx-controller-fips-1.14pkg:apk/chainguard/ingress-nginx-controller-fips-1.15pkg:apk/wolfi/ingress-nginx-controller-1.13pkg:apk/wolfi/ingress-nginx-controller-1.14pkg:apk/wolfi/ingress-nginx-controller-1.15pkg:bitnami/nginxpkg:bitnami/nginx-gatewaypkg:rpm/opensuse/nginx&distro=openSUSE%20Tumbleweed
< 1.13.8-r0+ 11 more
- (no CPE)range: < 1.13.8-r0
- (no CPE)range: < 1.14.0-r0
- (no CPE)range: < 1.15.0-r0
- (no CPE)range: < 1.13.0-r0
- (no CPE)range: < 1.14.0-r0
- (no CPE)range: < 1.15.0-r0
- (no CPE)range: < 1.13.8-r0
- (no CPE)range: < 1.14.0-r0
- (no CPE)range: < 1.15.0-r0
- (no CPE)range: >= 1.11.4, < 1.26.3
- (no CPE)range: >= 1.11.4, < 1.26.3
- (no CPE)range: < 1.27.4-1.1
- Range: R17
Patches
Vulnerability mechanics
References
3- www.openwall.com/lists/oss-security/2025/02/05/8nvdMailing ListThird Party Advisory
- lists.debian.org/debian-lts-announce/2025/03/msg00017.htmlnvdIssue TrackingThird Party Advisory
- my.f5.com/manage/s/article/K000149173nvdVendor Advisory
News mentions
0No linked articles in our index yet.