Bitnami package
nginx-agent
pkg:bitnami/nginx-agent
Vulnerabilities (3)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-60062 | Med | 6.4 | >= 2.37.0, < 2.47.0 | 2.47.0 | Jul 15, 2026 | The NGINX Agent config_dirs directive allows a low-privileged attacker to gain limited read and write access to files outside of the designated secure directory. The config_dirs directive required for this issue can also be configured through NGINX Instance Manager. A successful | |
| CVE-2024-7634 | Med | 4.9 | >= 2.17.0, < 2.37.0 | 2.37.0 | Aug 22, 2024 | NGINX Agent's "config_dirs" restriction feature allows a highly privileged attacker to gain the ability to write/overwrite files outside of the designated secure directory. | |
| CVE-2023-1550 | Med | 5.5 | >= 2.0.0, < 2.23.3 | 2.23.3 | Mar 29, 2023 | Insertion of Sensitive Information into log file vulnerability in NGINX Agent. NGINX Agent version 2.0 before 2.23.3 inserts sensitive information into a log file. An authenticated attacker with local access to read agent log files may gain access to private keys. This issue is o |
- affected >= 2.37.0, < 2.47.0fixed 2.47.0
The NGINX Agent config_dirs directive allows a low-privileged attacker to gain limited read and write access to files outside of the designated secure directory. The config_dirs directive required for this issue can also be configured through NGINX Instance Manager. A successful
- affected >= 2.17.0, < 2.37.0fixed 2.37.0
NGINX Agent's "config_dirs" restriction feature allows a highly privileged attacker to gain the ability to write/overwrite files outside of the designated secure directory.
- affected >= 2.0.0, < 2.23.3fixed 2.23.3
Insertion of Sensitive Information into log file vulnerability in NGINX Agent. NGINX Agent version 2.0 before 2.23.3 inserts sensitive information into a log file. An authenticated attacker with local access to read agent log files may gain access to private keys. This issue is o