First published: Thu Aug 22 2024(Updated: )
NGINX Agent's "config_dirs" restriction feature allows a highly privileged attacker to gain the ability to write/overwrite files outside of the designated secure directory.
Credit: f5sirt@f5.com
Affected Software | Affected Version | How to fix |
---|---|---|
F5 NGINX Agent | >=2.17.0<=2.36.1 | 2.37.0 |
F5 NGINX Instance Manager | >=2.3.1<=2.17.1=3 | 2.17.2 |
F5 NGINX Agent | >=2.17.0<2.37.0 | |
F5 NGINX Instance Manager | >=2.3.1<2.17.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-7634 is classified as a high-severity vulnerability due to the potential for file overwrite by a privileged attacker.
To fix CVE-2024-7634, upgrade to NGINX Agent version 2.37.0 or later, or NGINX Instance Manager version 2.17.2 or later.
CVE-2024-7634 addresses a flaw in the config_dirs restriction feature of the NGINX Agent which can be exploited for unauthorized file writes.
CVE-2024-7634 affects F5 NGINX Agent versions between 2.17.0 and 2.36.1 and F5 NGINX Instance Manager versions between 2.3.1 and 2.17.1.
CVE-2024-7634 allows a highly privileged attacker to overwrite files outside the secure directory, posing a risk of data manipulation and loss.