Description

NGINX Plus is a software load balancer, web server, and content cache built on top of open source NGINX. NGINX Plus has exclusive enterprise grade features beyond what's available in the open source offering, including session persistence, configuration via API, and active health checks.

NGINX Plus comes with a Live Activity Monitoring web based dashboard. Acunetix determined that it was possible to access this dashboard without authentication.

It's recommended to restrict access to the NGINX+ Dashboard as it may contain information that could be useful for an attacker.

Remediation

Restrict access to the NGINX+ Dashboard.

References

Related Vulnerabilities