Incorrect default permissions in NGINX Controller - CVE-2021-23021
Published: May 25, 2021
Vulnerability identifier: #VU53576
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-23021
CWE-ID: CWE-276
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to incorrect default permissions for agent configuration file /etc/controller-agent/agent.conf. A local user with access to the system can obtain sensitive information, such as the API key.
Affected software
NGINX Controller
IBM Cloud Pak for Business Automation
IBM Cloud Pak for Business Automation
How to mitigate CVE-2021-23021
Install updates from vendor's website.
NGINX Controller - update to 3.7.0
IBM Cloud Pak for Business Automation - update to 22.0.1.1
IBM Cloud Pak for Business Automation - update to 22.0.1.1