CVE-2013-0337
published 2013-10-27CVE-2013-0337: The default configuration of nginx, possibly 1.3.13 and earlier, uses world-readable permissions for the (1) access.log and (2) error.log files, which allows…
PriorityP432high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
1.91%
77.4th percentile
The default configuration of nginx, possibly 1.3.13 and earlier, uses world-readable permissions for the (1) access.log and (2) error.log files, which allows local users to obtain sensitive information by reading the files.
Affected
53 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | nginx | — | — |
| f5 | nginx | <= 1.3.13 | — |
| f5 | nginx | — | — |
| f5 | nginx | — | — |
| f5 | nginx | — | — |
| f5 | nginx | — | — |
| f5 | nginx | — | — |
| f5 | nginx | — | — |
| f5 | nginx | — | — |
| f5 | nginx | — | — |
| f5 | nginx | — | — |
| f5 | nginx | — | — |
| f5 | nginx | — | — |
| f5 | nginx | — | — |
| f5 | nginx | — | — |
| f5 | nginx | — | — |
| f5 | nginx | — | — |
| f5 | nginx | — | — |
| f5 | nginx | — | — |
| f5 | nginx | — | — |
| f5 | nginx | — | — |
| f5 | nginx | — | — |
| f5 | nginx | — | — |
| f5 | nginx | — | — |
| f5 | nginx | — | — |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_debian7.5LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-9ph7-v5fx-qwxf: The default configuration of nginx, possibly 1
ghsa_unreviewed·2022-05-05
CVE-2013-0337 [HIGH] GHSA-9ph7-v5fx-qwxf: The default configuration of nginx, possibly 1
The default configuration of nginx, possibly 1.3.13 and earlier, uses world-readable permissions for the (1) access.log and (2) error.log files, which allows local users to obtain sensitive information by reading the files.
OSV
CVE-2013-0337: The default configuration of nginx, possibly 1
osv·2013-10-27·CVSS 7.5
CVE-2013-0337 [HIGH] CVE-2013-0337: The default configuration of nginx, possibly 1
The default configuration of nginx, possibly 1.3.13 and earlier, uses world-readable permissions for the (1) access.log and (2) error.log files, which allows local users to obtain sensitive information by reading the files.
Palo Alto
PAN-SA-2020-0006 PAN-OS: Nginx software upgraded to resolve multiple vulnerabilities
vendor_paloalto·2020-05-13·CVSS 7.5
CVE-2016-4450 [HIGH] CWE-476 PAN-SA-2020-0006 PAN-OS: Nginx software upgraded to resolve multiple vulnerabilities
PAN-SA-2020-0006 PAN-OS: Nginx software upgraded to resolve multiple vulnerabilities
Nginx software included with PAN-OS has been upgraded to resolve multiple vulnerabilities. This issue affects: All PAN-OS 7.1 and 8.0 versions; PAN-OS 8.1 versions earlier than 8.1.14; PAN-OS 9.0 versions earlier than 9.0.7. The resolved vulnerabilities include: CVE CVSS Summary CVE-2016-4450 7.5 ( CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H ) os/unix/ngx_files.c in nginx before 1.10.1 and 1.11.x before 1.11.1 allows remote attackers to cause a denial of service (NULL pointer dereference and worker process crash) via a crafted request, involving writing a client request body to a temporary file. CVE-2013-0337 7.5 AV:N/AC:L/Au:N/C:P/I:P/A:P The default configuration of nginx, possibly 1.3.13 and earlier,
Debian
CVE-2013-0337: nginx - The default configuration of nginx, possibly 1.3.13 and earlier, uses world-read...
vendor_debian·2013·CVSS 7.5
CVE-2013-0337 [HIGH] CVE-2013-0337: nginx - The default configuration of nginx, possibly 1.3.13 and earlier, uses world-read...
The default configuration of nginx, possibly 1.3.13 and earlier, uses world-readable permissions for the (1) access.log and (2) error.log files, which allows local users to obtain sensitive information by reading the files.
Scope: local
bookworm: open
bullseye: open
forky: open
sid: open
trixie: open
No detection rules found.
No public exploits indexed.
http://secunia.com/advisories/55181http://security.gentoo.org/glsa/glsa-201310-04.xmlhttp://www.openwall.com/lists/oss-security/2013/02/21/15http://www.openwall.com/lists/oss-security/2013/02/22/1http://www.openwall.com/lists/oss-security/2013/02/24/1http://secunia.com/advisories/55181http://security.gentoo.org/glsa/glsa-201310-04.xmlhttp://www.openwall.com/lists/oss-security/2013/02/21/15http://www.openwall.com/lists/oss-security/2013/02/22/1http://www.openwall.com/lists/oss-security/2013/02/24/1
2013-10-27
Published