Security Advisory Description When NGINX Plus is configured to use the MQTT filter module, undisclosed requests can cause an increase in memory resource utilization. (CVE-2024-39792) Impact System performance can degrade until the NGINX master and worker processes are either forced to restart or are manually restarted. This vulnerability allows a remote, unauthenticated attacker to cause a degradation of service that can lead to a denial-of-service (DoS) of NGINX. There is no control plane exposure; this is a data plane issue only. Note: For information about NGINX master and worker processes, refer to Controlling NGINX Processes at Runtime. Note: F5 is working to eliminate exclusionary language in our products and documentation. For more information, refer to K34150231: Exclusionary language in F5 products and…Read More
