CVE-2013-0337F5 Nginx vulnerability

CWE-2646 documents6 sources
Severity
7.5HIGHNVD
EPSS
0.6%
top 29.86%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedOct 27
Latest updateMay 5

Description

The default configuration of nginx, possibly 1.3.13 and earlier, uses world-readable permissions for the (1) access.log and (2) error.log files, which allows local users to obtain sensitive information by reading the files.

CVSS vector

AV:N/AC:L/C:P/I:P/A:PExploitability: 10.0 | Impact: 6.4

Affected Packages1 packages

NVDf5/nginx1.3.13+50

🔴Vulnerability Details

3
GHSA
GHSA-9ph7-v5fx-qwxf: The default configuration of nginx, possibly 12022-05-05
CVEList
CVE-2013-0337: The default configuration of nginx, possibly 12013-10-27
OSV
CVE-2013-0337: The default configuration of nginx, possibly 12013-10-27

📋Vendor Advisories

1
Debian
CVE-2013-0337: nginx - The default configuration of nginx, possibly 1.3.13 and earlier, uses world-read...2013

💬Community

1
Bugzilla
CVE-2013-0337 nginx: world-readable log files2013-02-21
CVE-2013-0337 — F5 Nginx vulnerability | cvebase