Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-68qv-j282-p3jm

Опубликовано: 29 мар. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 5.5

Описание

Insertion of Sensitive Information into log file vulnerability in NGINX Agent. NGINX Agent version 2.0 before 2.23.3 inserts sensitive information into a log file. An authenticated attacker with local access to read agent log files may gain access to private keys. This issue is only exposed when the non-default trace level logging is enabled. Note: NGINX Agent is included with NGINX Instance Manager and used in conjunction with NGINX API Connectivity Manager, and NGINX Management Suite Security Monitoring.

Insertion of Sensitive Information into log file vulnerability in NGINX Agent. NGINX Agent version 2.0 before 2.23.3 inserts sensitive information into a log file. An authenticated attacker with local access to read agent log files may gain access to private keys. This issue is only exposed when the non-default trace level logging is enabled. Note: NGINX Agent is included with NGINX Instance Manager and used in conjunction with NGINX API Connectivity Manager, and NGINX Management Suite Security Monitoring.

EPSS

Процентиль: 29%
0.00106
Низкий

5.5 Medium

CVSS3

Дефекты

CWE-532

Связанные уязвимости

CVSS3: 5.5
nvd
почти 3 года назад

Insertion of Sensitive Information into log file vulnerability in NGINX Agent. NGINX Agent version 2.0 before 2.23.3 inserts sensitive information into a log file. An authenticated attacker with local access to read agent log files may gain access to private keys. This issue is only exposed when the non-default trace level logging is enabled. Note: NGINX Agent is included with NGINX Instance Manager and used in conjunction with NGINX API Connectivity Manager, and NGINX Management Suite Security Monitoring.

CVSS3: 5.5
fstec
почти 3 года назад

Уязвимость демона NGINX Agent и платформы автоматизации NGINX Instance Manager, связанная с недостаточной защитой регистрационных данных, позволяющая нарушителю получить доступ к закрытым ключам

EPSS

Процентиль: 29%
0.00106
Низкий

5.5 Medium

CVSS3

Дефекты

CWE-532