Show filters
2 Total Results
Displaying 1-2 of 2
Sort by:
Attacker Value
Unknown

CVE-2021-25742

Disclosure Date: October 29, 2021 (last updated February 23, 2025)
A security issue was discovered in ingress-nginx where a user that can create or update ingress objects can use the custom snippets feature to obtain all secrets in the cluster.
Attacker Value
Unknown

CVE-2013-0337

Disclosure Date: October 27, 2013 (last updated October 05, 2023)
The default configuration of nginx, possibly 1.3.13 and earlier, uses world-readable permissions for the (1) access.log and (2) error.log files, which allows local users to obtain sensitive information by reading the files.
0