Lucene search

K
cveRedhatCVE-2013-0337
HistoryOct 27, 2013 - 12:55 a.m.

CVE-2013-0337

2013-10-2700:55:03
CWE-264
redhat
web.nvd.nist.gov
207
cve
2013
0337
nginx
default configuration
vulnerability
security
nvd

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

5.7

Confidence

Low

EPSS

0.002

Percentile

56.9%

The default configuration of nginx, possibly 1.3.13 and earlier, uses world-readable permissions for the (1) access.log and (2) error.log files, which allows local users to obtain sensitive information by reading the files.

Affected configurations

Nvd
Node
f5nginxRangeโ‰ค1.3.13
OR
f5nginxMatch1.0.0
OR
f5nginxMatch1.0.1
OR
f5nginxMatch1.0.2
OR
f5nginxMatch1.0.3
OR
f5nginxMatch1.0.4
OR
f5nginxMatch1.0.5
OR
f5nginxMatch1.0.6
OR
f5nginxMatch1.0.7
OR
f5nginxMatch1.0.8
OR
f5nginxMatch1.0.9
OR
f5nginxMatch1.0.10
OR
f5nginxMatch1.0.11
OR
f5nginxMatch1.0.12
OR
f5nginxMatch1.0.13
OR
f5nginxMatch1.0.14
OR
f5nginxMatch1.0.15
OR
f5nginxMatch1.1.0
OR
f5nginxMatch1.1.1
OR
f5nginxMatch1.1.2
OR
f5nginxMatch1.1.3
OR
f5nginxMatch1.1.4
OR
f5nginxMatch1.1.5
OR
f5nginxMatch1.1.6
OR
f5nginxMatch1.1.7
OR
f5nginxMatch1.1.8
OR
f5nginxMatch1.1.9
OR
f5nginxMatch1.1.10
OR
f5nginxMatch1.1.11
OR
f5nginxMatch1.1.12
OR
f5nginxMatch1.1.13
OR
f5nginxMatch1.1.14
OR
f5nginxMatch1.1.15
OR
f5nginxMatch1.1.16
OR
f5nginxMatch1.1.17
OR
f5nginxMatch1.1.18
OR
f5nginxMatch1.1.19
OR
f5nginxMatch1.2.0
OR
f5nginxMatch1.3.0
OR
f5nginxMatch1.3.1
OR
f5nginxMatch1.3.2
OR
f5nginxMatch1.3.3
OR
f5nginxMatch1.3.4
OR
f5nginxMatch1.3.5
OR
f5nginxMatch1.3.6
OR
f5nginxMatch1.3.7
OR
f5nginxMatch1.3.8
OR
f5nginxMatch1.3.9
OR
f5nginxMatch1.3.10
OR
f5nginxMatch1.3.11
OR
f5nginxMatch1.3.12
VendorProductVersionCPE
f5nginx*cpe:2.3:a:f5:nginx:*:*:*:*:*:*:*:*
f5nginx1.0.0cpe:2.3:a:f5:nginx:1.0.0:*:*:*:*:*:*:*
f5nginx1.0.1cpe:2.3:a:f5:nginx:1.0.1:*:*:*:*:*:*:*
f5nginx1.0.2cpe:2.3:a:f5:nginx:1.0.2:*:*:*:*:*:*:*
f5nginx1.0.3cpe:2.3:a:f5:nginx:1.0.3:*:*:*:*:*:*:*
f5nginx1.0.4cpe:2.3:a:f5:nginx:1.0.4:*:*:*:*:*:*:*
f5nginx1.0.5cpe:2.3:a:f5:nginx:1.0.5:*:*:*:*:*:*:*
f5nginx1.0.6cpe:2.3:a:f5:nginx:1.0.6:*:*:*:*:*:*:*
f5nginx1.0.7cpe:2.3:a:f5:nginx:1.0.7:*:*:*:*:*:*:*
f5nginx1.0.8cpe:2.3:a:f5:nginx:1.0.8:*:*:*:*:*:*:*
Rows per page:
1-10 of 511

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

5.7

Confidence

Low

EPSS

0.002

Percentile

56.9%