PT-2023-2758 · Nginx · Nginx Management Suite+3

Published

2023-04-14

·

Updated

2025-05-19

·

CVE-2023-28656

CVSS v2.0

8.5

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:N
Name of the Vulnerable Software and Affected Versions NGINX Management Suite (affected versions not specified) NGINX Instance Manager (affected versions not specified) NGINX API Connectivity Manager (affected versions not specified) NGINX Security Monitoring (affected versions not specified)
Description The issue allows an authenticated attacker to gain access to configuration objects outside of their assigned environment. This is related to an authorization bypass vulnerability using a user-controlled key, which can be exploited by a remote attacker to bypass security restrictions and gain read, modify, or delete access to data.
Recommendations For NGINX Management Suite, consider restricting access to configuration objects to minimize the risk of exploitation until a patch is available. For NGINX Instance Manager, temporarily disable the use of user-controlled keys to prevent authorization bypass. For NGINX API Connectivity Manager, restrict access to sensitive data to prevent unauthorized modification or deletion. For NGINX Security Monitoring, consider implementing additional security measures to prevent exploitation of the authorization bypass vulnerability. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

IDOR

Weakness Enumeration

Related Identifiers

BDU:2023-02620
CVE-2023-28656

Affected Products

Nginx Api Connectivity Manager
Nginx Instance Manager
Nginx Management Suite
Nginx Security Monitoring