Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-1550


Insertion of Sensitive Information into log file vulnerability in NGINX Agent. NGINX Agent version 2.0 before 2.23.3 inserts sensitive information into a log file. An authenticated attacker with local access to read agent log files may gain access to private keys. This issue is only exposed when the non-default trace level logging is enabled. Note: NGINX Agent is included with NGINX Instance Manager and used in conjunction with NGINX API Connectivity Manager, and NGINX Management Suite Security Monitoring.


Published

2023-03-29T17:15:07.107

Last Modified

2024-11-21T07:39:25.473

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 5.5 (MEDIUM)

Weaknesses
  • Type: Primary
    CWE-532

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application f5 nginx_agent < 2.23.3 Yes
Application f5 nginx_instance_manager < 2.9.0 Yes

References