PT-2024-6180 · Nginx · Nginx Agent

Published

2024-08-22

·

Updated

2024-08-23

·

CVE-2024-7634

CVSS v2.0

6.8

Medium

VectorAV:N/AC:L/Au:S/C:N/I:C/A:N
Name of the Vulnerable Software and Affected Versions NGINX Agent (affected versions not specified)
Description The issue is related to the config dirs function of the NGINX Agent and NGINX Instance Manager platform, which allows an attacker to upload arbitrary files outside the intended directory. This can enable a remote attacker to write or overwrite arbitrary files. The exploitation requires a highly privileged attacker.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Path traversal

Weakness Enumeration

Related Identifiers

BDU:2024-07101
BIT-NGINX-AGENT-2024-7634
CVE-2024-7634

Affected Products

Nginx Agent