CVE-2023-1550

CVSS V2 None CVSS V3 None
Description
Insertion of Sensitive Information into log file vulnerability in NGINX Agent. NGINX Agent version 2.0 before 2.23.3 inserts sensitive information into a log file. An authenticated attacker with local access to read agent log files may gain access to private keys. This issue is only exposed when the non-default trace level logging is enabled. Note: NGINX Agent is included with NGINX Instance Manager and used in conjunction with NGINX API Connectivity Manager, and NGINX Management Suite Security Monitoring.
Overview
  • CVE ID
  • CVE-2023-1550
  • Assigner
  • f5sirt@f5.com
  • Vulnerability Status
  • Analyzed
  • Published Version
  • 2023-03-29T17:15:07
  • Last Modified Date
  • 2023-04-05T12:59:01
CPE Configuration (Product)
CPE Vulnerable Operator Version Start Version End
cpe:2.3:a:f5:nginx_agent:*:*:*:*:*:*:*:* 1 OR 2.0.0 2.23.3
cpe:2.3:a:f5:nginx_instance_manager:*:*:*:*:*:*:*:* 1 OR 2.0.0 2.9.0
References
Reference URL Reference Tags
https://my.f5.com/manage/s/article/K000133135 Vendor Advisory
History
Created Old Value New Value Data Type Notes
2023-04-17 03:46:19 Added to TrackCVE
2023-04-17 03:46:21 Weakness Enumeration new