CVE-2024-7634: NGINX Agent Vulnerability
NGINX Agent's "configdirs" restriction feature allows a highly privileged attacker to gain the ability to write/overwrite files outside of the designated secure directory.
Other sources
NGINX Agent's configdirs restriction feature allows a highly privileged attacker to gain the ability to write/overwrite files outside of the designated secure directory.
— F5
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-7634?
CVE-2024-7634 is classified as a high-severity vulnerability due to the potential for file overwrite by a privileged attacker.
How do I fix CVE-2024-7634?
To fix CVE-2024-7634, upgrade to NGINX Agent version 2.37.0 or later, or NGINX Instance Manager version 2.17.2 or later.
What vulnerability does CVE-2024-7634 address?
CVE-2024-7634 addresses a flaw in the config_dirs restriction feature of the NGINX Agent which can be exploited for unauthorized file writes.
Who is affected by CVE-2024-7634?
CVE-2024-7634 affects F5 NGINX Agent versions between 2.17.0 and 2.36.1 and F5 NGINX Instance Manager versions between 2.3.1 and 2.17.1.
What type of attack can be executed using CVE-2024-7634?
CVE-2024-7634 allows a highly privileged attacker to overwrite files outside the secure directory, posing a risk of data manipulation and loss.