QID 730138
Date Published: 2021-07-22
QID 730138: Nginx plus API unauthenticated detected
NGINX+ contains a ngx_http_api_module module. The ngx_http_api_module module (1.13.3) provides REST API for accessing various status information, configuring upstream server groups on-the-fly, and managing key-value pairs without the need of reconfiguring nginx.
Affected Versions:
NGINX Plus API
QID Detection Logic (Unauthenticated):
This QID tries to send HTTP GET request to /api/1 and /api/1/nginx.
An unauthenticated remote attacker may exploit this vulnerability to retrieve sensitive information.
Solution
Customers are advised to update to Restrict access to the NGINX+ API interface or later to remediate these vulnerabilities.
Vendor References
CVEs related to QID 730138
Software Advisories
| Advisory ID | Software | Component | Link |
|---|