Back to search
CVE-2013-0337
Published: Oct 27, 2013
Modified: Aug 6, 2024
PUBLISHED
Description
The default configuration of nginx, possibly 1.3.13 and earlier, uses world-readable permissions for the (1) access.log and (2) error.log files, which allows local users to obtain sensitive information by reading the files.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
55181
third-party-advisory
x_refsource_SECUNIA
[oss-security] 20130224 nginx CVE-2013-0337 world-readable logs
mailing-list
x_refsource_MLIST
[oss-security] 20130221 Re: CVE request: nginx world-readable logdir
mailing-list
x_refsource_MLIST
GLSA-201310-04
vendor-advisory
x_refsource_GENTOO
[oss-security] 20130221 nginx world-readable logdir
mailing-list
x_refsource_MLIST
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now