CVE-2023-1550
published 2023-03-29CVE-2023-1550: Insertion of Sensitive Information into log file vulnerability in NGINX Agent. NGINX Agent version 2.0 before 2.23.3 inserts sensitive information into a log…
PriorityP425medium5.5CVSS 3.1
AVLACLPRLUINSUCHINAN
EPSS
0.22%
12.3th percentile
Insertion of Sensitive Information into log file vulnerability in NGINX Agent. NGINX Agent version 2.0 before 2.23.3 inserts sensitive information into a log file. An authenticated attacker with local access to read agent log files may gain access to private keys. This issue is only exposed when the non-default trace level logging is enabled. Note: NGINX Agent is included with NGINX Instance Manager and used in conjunction with NGINX API Connectivity Manager, and NGINX Management Suite Security Monitoring.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| f5 | nginx_agent | — | — |
| f5 | nginx_agent | >= 2.0 < 2.23.3 | 2.23.3 |
| f5 | nginx_agent | >= 2.0.0 < 2.23.3 | 2.23.3 |
| f5 | nginx_instance_manager | — | — |
| f5 | nginx_instance_manager | >= 2.0.0 < 2.9.0 | 2.9.0 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-68qv-j282-p3jm: Insertion of Sensitive Information into log file vulnerability in NGINX Agent
ghsa_unreviewed·2023-03-29
CVE-2023-1550 [MEDIUM] CWE-532 GHSA-68qv-j282-p3jm: Insertion of Sensitive Information into log file vulnerability in NGINX Agent
Insertion of Sensitive Information into log file vulnerability in NGINX Agent. NGINX Agent version 2.0 before 2.23.3 inserts sensitive information into a log file. An authenticated attacker with local access to read agent log files may gain access to private keys. This issue is only exposed when the non-default trace level logging is enabled. Note: NGINX Agent is included with NGINX Instance Manager and used in conjunction with NGINX API Connectivity Manager, and NGINX Management Suite Security Monitoring.
F5
CVE-2023-1550: Insertion of Sensitive Information into log file vulnerability in NGINX Agent
vendor_f5·2023-03-29·CVSS 5.5
CVE-2023-1550 [MEDIUM] CWE-532 CVE-2023-1550: Insertion of Sensitive Information into log file vulnerability in NGINX Agent
CVE-2023-1550: Insertion of Sensitive Information into log file vulnerability in NGINX Agent
Insertion of Sensitive Information into log file vulnerability in NGINX Agent. NGINX Agent version 2.0 before 2.23.3 inserts sensitive information into a log file. An authenticated attacker with local access to read agent log files may gain access to private keys. This issue is only exposed when the non-default trace level logging is enabled. Note: NGINX Agent is included with NGINX Instance Manager and used in conjunction with NGINX API Connectivity Manager, and NGINX Management Suite Security Monitoring.
Affected Products: Nginx Agent, Nginx Instance Manager
Affected Versions: 2.0.0 - 2.23.3; 2.0.0 - 2.9.0
F5 Advisory Articles: K000133135
F5 References: https://my.f5.com/manage/s/article/K00013
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-03-29
Published