CVE-2013-0337 PUBLISHED

The default configuration of nginx, possibly 1.3.13 and earlier, uses world-readable permissions for the (1) access.log and (2) error.log files, which allows local users to obtain sensitive information by reading the files.

EPSS 0.62% · 69.9th percentile

Risk Scores

EPSS Score
0.62%
69.9th percentile

Affected Products

VendorProductVersions
Ubuntu:Pro:16.04:LTSnginx1.9.10-1ubuntu1, 1.9.11-0ubuntu2, 1.9.12-0ubuntu1
Cloudflareaccess
AWSconfig
Ubuntu:Pro:14.04:LTSnginx1.4.6-1ubuntu3.9+esm1, 1.4.1-3ubuntu1, 1.4.3-2ubuntu1
Ubuntu:Pro:18.04:LTSnginx1.13.6-2ubuntu1, 1.13.6-2ubuntu2, 1.13.10-1ubuntu1

Timeline

References

Open in Interactive Console →