CVE-2013-0337
EPSS 0.64%
Description
The default configuration of nginx, possibly 1.3.13 and earlier, uses world-readable permissions for the (1) access.log and (2) error.log files, which allows local users to obtain sensitive information by reading the files.
How to fix CVE-2013-0337
No fixed version has been published yet. Mitigate by removing the affected package or applying upstream guidance from the references below.
- Debian/nginx—no fix listed
Is CVE-2013-0337 being exploited?
Low — EPSS is 0.6%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0