CVE-2013-0337: High severity f5 nginx vulnerability
The default configuration of nginx, possibly 1.3.13 and earlier, uses world-readable permissions for the (1) access.log and (2) error.log files, which allows local users to obtain sensitive information by reading the files.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-0337?
CVE-2013-0337 has been classified as a moderate severity vulnerability due to the potential exposure of sensitive log information.
How do I mitigate CVE-2013-0337?
To mitigate CVE-2013-0337, ensure that access.log and error.log files are configured with appropriate file permissions to restrict read access.
Which versions of nginx are affected by CVE-2013-0337?
CVE-2013-0337 affects nginx versions 1.3.13 and earlier, along with all versions from 1.0.0 to 1.3.12.
What type of vulnerability is CVE-2013-0337?
CVE-2013-0337 is a security misconfiguration vulnerability that allows local users to read sensitive log file information.
Is there a fix available for CVE-2013-0337?
Yes, updating nginx to version 1.3.14 or later will resolve the vulnerability associated with CVE-2013-0337.