{"id":"CVE-2013-4547","details":"nginx 0.8.41 through 1.4.3 and 1.5.x before 1.5.7 allows remote attackers to bypass intended restrictions via an unescaped space character in a URI.","modified":"2026-04-16T06:22:10.004223477Z","published":"2013-11-23T18:55:04Z","related":["openSUSE-SU-2024:10044-1","openSUSE-SU-2024:11341-1"],"references":[{"type":"ADVISORY","url":"http://lists.opensuse.org/opensuse-security-announce/2013-12/msg00007.html"},{"type":"ADVISORY","url":"http://lists.opensuse.org/opensuse-updates/2013-11/msg00084.html"},{"type":"ADVISORY","url":"http://lists.opensuse.org/opensuse-updates/2013-11/msg00118.html"},{"type":"ADVISORY","url":"http://lists.opensuse.org/opensuse-updates/2013-11/msg00119.html"},{"type":"ADVISORY","url":"http://mailman.nginx.org/pipermail/nginx-announce/2013/000125.html"},{"type":"ADVISORY","url":"http://secunia.com/advisories/55757"},{"type":"ADVISORY","url":"http://secunia.com/advisories/55822"},{"type":"ADVISORY","url":"http://secunia.com/advisories/55825"},{"type":"ADVISORY","url":"http://www.debian.org/security/2012/dsa-2802"},{"type":"ARTICLE","url":"http://lists.opensuse.org/opensuse-security-announce/2013-12/msg00007.html"},{"type":"ARTICLE","url":"http://lists.opensuse.org/opensuse-updates/2013-11/msg00084.html"},{"type":"ARTICLE","url":"http://lists.opensuse.org/opensuse-updates/2013-11/msg00118.html"},{"type":"ARTICLE","url":"http://lists.opensuse.org/opensuse-updates/2013-11/msg00119.html"},{"type":"WEB","url":"http://mailman.nginx.org/pipermail/nginx-announce/2013/000125.html"}],"schema_version":"1.7.5"}