GSD-2022-1000285

    Dashboard / Vulnerabilities / GSD-2022-1000285

    GSD-2022-1000285

    Published: 23 Feb 2022Last Modified: 14 Mar 2023

    Summary: Unsafe default configuration values in Nginx version all version

    Details: # INFORMATIONAL In Nginx, all versions, a number of unsafe default configuration values exists in the web server that can be attacked via the network resulting in disclosure of information and availability. These include but are not limited to: 1. Not enough file descriptors per worker 2. The error_log off directive 3. Not enabling keepalive connections to upstream servers 4. Forgetting how directive inheritance works 5. The proxy_buffering off directive 6. Improper use of the if directive 7. Excessive health checks 8. Unsecured access to metrics 9. Using ip_hash when all traffic comes from the same /24 CIDR block 10. Not taking advantage of upstream groups

    Affected packages

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GSD-2022-1000285 | CVE-DB