The NGINX Agent config_dirs directive allows a low-privileged attacker to gain limited read and write access to files outside of the designated secure directory. The config_dirs directive required for this issue can also be configured through NGINX Instance Manager. A successful exploit may allow an attacker to cross a security boundary.
Impact:
A remotely authenticated low-privileged attacker could gain limited read and write access outside of the list of directories specified in the NGINX Agent configuration. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Attack Parameters
Impact Assessment
CVSS Vector v4.0
Weakness Type (CWE)
Vulnerable Products 2
| Configuration | From (including) | Up to (excluding) |
|---|---|---|
|
F5 Nginx_Agent
cpe:2.3:a:f5:nginx_agent:*:*:*:*:*:*:*:*
|
2.37.0
|
2.46.7
|
|
F5 Nginx_Instance_Manager
cpe:2.3:a:f5:nginx_instance_manager:*:*:*:*:*:*:*:*
|
2.17.1
|
2.22.2
|