ZeroHour

CVE-2020-5865

CVSS 3.1
4.8 medium
EPSS
<1%p33
Published
()
Modified
Description

In versions prior to 3.3.0, the NGINX Controller is configured to communicate with its Postgres database server over unencrypted channels, making the communicated data vulnerable to interception via man-in-the-middle (MiTM) attacks.

Vendors
f5netapp
Products
nginx controller, cloud backup
Weakness
CWE-319
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.