World Readable Configuration File in Nginx Controller 3.x by F5 Networks
CVE-2021-23021
5.5MEDIUM
What is CVE-2021-23021?
The Nginx Controller 3.x, prior to version 3.7.0, has a vulnerability where the agent configuration file located at /etc/controller-agent/agent.conf is accessible to all users due to its file permissions being set to 644. This exposure could allow unauthorized access to sensitive configuration information, potentially leading to further exploitation within the system.
Affected Version(s)
Nginx Controller “3.x before 3.7.0”