CyberRota Analysis
AI-GeneratedThe NGINX Agent's config_dirs directive is vulnerable, allowing low-privileged authenticated attackers to gain limited read and write access to files outside the designated secure directory. This could enable attackers to cross security boundaries and potentially compromise sensitive data. Organizations using NGINX, particularly those with remote access configurations, should prioritize addressing this vulnerability to mitigate the risk of unauthorized data exposure.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
The NGINX Agent config_dirs directive allows a low-privileged attacker to gain limited read and write access to files outside of the designated secure directory. The config_dirs directive required for this issue can also be configured through NGINX Instance Manager. A successful exploit may allow an attacker to cross a security boundary. Impact: A remotely authenticated low-privileged attacker could gain limited read and write access outside of the list of directories specified in the NGINX Agent configuration. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Related CVEs
Other vulnerabilities affecting the same vendor(s)