Логотип exploitDog
bind:CVE-2023-1550
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2023-1550

Количество 3

Количество 3

nvd логотип

CVE-2023-1550

почти 3 года назад

Insertion of Sensitive Information into log file vulnerability in NGINX Agent. NGINX Agent version 2.0 before 2.23.3 inserts sensitive information into a log file. An authenticated attacker with local access to read agent log files may gain access to private keys. This issue is only exposed when the non-default trace level logging is enabled. Note: NGINX Agent is included with NGINX Instance Manager and used in conjunction with NGINX API Connectivity Manager, and NGINX Management Suite Security Monitoring.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-68qv-j282-p3jm

почти 3 года назад

Insertion of Sensitive Information into log file vulnerability in NGINX Agent. NGINX Agent version 2.0 before 2.23.3 inserts sensitive information into a log file. An authenticated attacker with local access to read agent log files may gain access to private keys. This issue is only exposed when the non-default trace level logging is enabled. Note: NGINX Agent is included with NGINX Instance Manager and used in conjunction with NGINX API Connectivity Manager, and NGINX Management Suite Security Monitoring.

CVSS3: 5.5
EPSS: Низкий
fstec логотип

BDU:2023-01923

почти 3 года назад

Уязвимость демона NGINX Agent и платформы автоматизации NGINX Instance Manager, связанная с недостаточной защитой регистрационных данных, позволяющая нарушителю получить доступ к закрытым ключам

CVSS3: 5.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2023-1550

Insertion of Sensitive Information into log file vulnerability in NGINX Agent. NGINX Agent version 2.0 before 2.23.3 inserts sensitive information into a log file. An authenticated attacker with local access to read agent log files may gain access to private keys. This issue is only exposed when the non-default trace level logging is enabled. Note: NGINX Agent is included with NGINX Instance Manager and used in conjunction with NGINX API Connectivity Manager, and NGINX Management Suite Security Monitoring.

CVSS3: 5.5
0%
Низкий
почти 3 года назад
github логотип
GHSA-68qv-j282-p3jm

Insertion of Sensitive Information into log file vulnerability in NGINX Agent. NGINX Agent version 2.0 before 2.23.3 inserts sensitive information into a log file. An authenticated attacker with local access to read agent log files may gain access to private keys. This issue is only exposed when the non-default trace level logging is enabled. Note: NGINX Agent is included with NGINX Instance Manager and used in conjunction with NGINX API Connectivity Manager, and NGINX Management Suite Security Monitoring.

CVSS3: 5.5
0%
Низкий
почти 3 года назад
fstec логотип
BDU:2023-01923

Уязвимость демона NGINX Agent и платформы автоматизации NGINX Instance Manager, связанная с недостаточной защитой регистрационных данных, позволяющая нарушителю получить доступ к закрытым ключам

CVSS3: 5.5
0%
Низкий
почти 3 года назад

Уязвимостей на страницу