VYPR

NGINX Agent

by Nginx

CVEs (3)

  • CVE-2023-1550MedMar 29, 2023
    risk 0.36cvss 5.5epss 0.00

    Insertion of Sensitive Information into log file vulnerability in NGINX Agent. NGINX Agent version 2.0 before 2.23.3 inserts sensitive information into a log file. An authenticated attacker with local access to read agent log files may gain access to private keys. This issue is…

  • CVE-2024-7634MedAug 22, 2024
    risk 0.32cvss 4.9epss 0.00

    NGINX Agent's "config_dirs" restriction feature allows a highly privileged attacker to gain the ability to write/overwrite files outside of the designated secure directory.

  • CVE-2026-60062Jul 15, 2026
    risk 0.00cvss epss 0.00

    The NGINX Agent config_dirs directive allows a low-privileged attacker to gain limited read and write access to files outside of the designated secure directory. The config_dirs directive required for this issue can also be configured through NGINX Instance Manager. A…