PT-2023-2758 · Nginx · Nginx Management Suite+3
Published
2023-04-14
·
Updated
2025-05-19
·
CVE-2023-28656
CVSS v2.0
8.5
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:N |
Name of the Vulnerable Software and Affected Versions
NGINX Management Suite (affected versions not specified)
NGINX Instance Manager (affected versions not specified)
NGINX API Connectivity Manager (affected versions not specified)
NGINX Security Monitoring (affected versions not specified)
Description
The issue allows an authenticated attacker to gain access to configuration objects outside of their assigned environment. This is related to an authorization bypass vulnerability using a user-controlled key, which can be exploited by a remote attacker to bypass security restrictions and gain read, modify, or delete access to data.
Recommendations
For NGINX Management Suite, consider restricting access to configuration objects to minimize the risk of exploitation until a patch is available.
For NGINX Instance Manager, temporarily disable the use of user-controlled keys to prevent authorization bypass.
For NGINX API Connectivity Manager, restrict access to sensitive data to prevent unauthorized modification or deletion.
For NGINX Security Monitoring, consider implementing additional security measures to prevent exploitation of the authorization bypass vulnerability.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Nginx Api Connectivity Manager
Nginx Instance Manager
Nginx Management Suite
Nginx Security Monitoring