World Readable Configuration File in Nginx Controller 3.x by F5 Networks
CVE-2021-23021

5.5MEDIUM

Key Information:

Vendor
F5
Vendor
CVE Published:
1 June 2021

Summary

The Nginx Controller 3.x, prior to version 3.7.0, has a vulnerability where the agent configuration file located at /etc/controller-agent/agent.conf is accessible to all users due to its file permissions being set to 644. This exposure could allow unauthorized access to sensitive configuration information, potentially leading to further exploitation within the system.

Affected Version(s)

Nginx Controller “3.x before 3.7.0”

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.