CVE Vulnerabilities

CVE-2013-0337

Published: Oct 27, 2013 | Modified: Apr 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
LOW
root.io logo minimus.io logo echo.ai logo

The default configuration of nginx, possibly 1.3.13 and earlier, uses world-readable permissions for the (1) access.log and (2) error.log files, which allows local users to obtain sensitive information by reading the files.

Affected Software

NameVendorStart VersionEnd Version
NginxF5*1.3.13 (including)
NginxF51.0.0 (including)1.0.0 (including)
NginxF51.0.1 (including)1.0.1 (including)
NginxF51.0.2 (including)1.0.2 (including)
NginxF51.0.3 (including)1.0.3 (including)
NginxF51.0.4 (including)1.0.4 (including)
NginxF51.0.5 (including)1.0.5 (including)
NginxF51.0.6 (including)1.0.6 (including)
NginxF51.0.7 (including)1.0.7 (including)
NginxF51.0.8 (including)1.0.8 (including)
NginxF51.0.9 (including)1.0.9 (including)
NginxF51.0.10 (including)1.0.10 (including)
NginxF51.0.11 (including)1.0.11 (including)
NginxF51.0.12 (including)1.0.12 (including)
NginxF51.0.13 (including)1.0.13 (including)
NginxF51.0.14 (including)1.0.14 (including)
NginxF51.0.15 (including)1.0.15 (including)
NginxF51.1.0 (including)1.1.0 (including)
NginxF51.1.1 (including)1.1.1 (including)
NginxF51.1.2 (including)1.1.2 (including)
NginxF51.1.3 (including)1.1.3 (including)
NginxF51.1.4 (including)1.1.4 (including)
NginxF51.1.5 (including)1.1.5 (including)
NginxF51.1.6 (including)1.1.6 (including)
NginxF51.1.7 (including)1.1.7 (including)
NginxF51.1.8 (including)1.1.8 (including)
NginxF51.1.9 (including)1.1.9 (including)
NginxF51.1.10 (including)1.1.10 (including)
NginxF51.1.11 (including)1.1.11 (including)
NginxF51.1.12 (including)1.1.12 (including)
NginxF51.1.13 (including)1.1.13 (including)
NginxF51.1.14 (including)1.1.14 (including)
NginxF51.1.15 (including)1.1.15 (including)
NginxF51.1.16 (including)1.1.16 (including)
NginxF51.1.17 (including)1.1.17 (including)
NginxF51.1.18 (including)1.1.18 (including)
NginxF51.1.19 (including)1.1.19 (including)
NginxF51.2.0 (including)1.2.0 (including)
NginxF51.3.0 (including)1.3.0 (including)
NginxF51.3.1 (including)1.3.1 (including)
NginxF51.3.2 (including)1.3.2 (including)
NginxF51.3.3 (including)1.3.3 (including)
NginxF51.3.4 (including)1.3.4 (including)
NginxF51.3.5 (including)1.3.5 (including)
NginxF51.3.6 (including)1.3.6 (including)
NginxF51.3.7 (including)1.3.7 (including)
NginxF51.3.8 (including)1.3.8 (including)
NginxF51.3.9 (including)1.3.9 (including)
NginxF51.3.10 (including)1.3.10 (including)
NginxF51.3.11 (including)1.3.11 (including)
NginxF51.3.12 (including)1.3.12 (including)
NginxUbuntuartful*
NginxUbuntubionic*
NginxUbuntudevel*
NginxUbuntuesm-infra-legacy/trusty*
NginxUbuntuesm-infra/bionic*
NginxUbuntuesm-infra/xenial*
NginxUbuntuhardy*
NginxUbuntulucid*
NginxUbuntuoneiric*
NginxUbuntuprecise*
NginxUbuntuquantal*
NginxUbunturaring*
NginxUbuntusaucy*
NginxUbuntutrusty*
NginxUbuntutrusty/esm*
NginxUbuntuupstream*
NginxUbuntuxenial*
NginxUbuntuyakkety*
NginxUbuntuzesty*

References