QID 375532
QID 375532: Nginx REST API vulnerability
NGINX+ contains a ngx_http_api_module module. The ngx_http_api_module module (1.13.3) provides REST API for accessing various status information, configuring upstream server groups on-the-fly, and managing key-value pairs without the need of reconfiguring nginx.
The host is allowing access to the NGINX API without requiring authentication, if the response shows nginx processes running.
QID Detection Logic (authenticated):
The authenticated check tries to fetch the version information of Nginx API
NA
Solution
NA
Vendor References
CVEs related to QID 375532
Software Advisories
| Advisory ID | Software | Component | Link |
|---|