ZeroHour

CVE-2020-5909

CVSS 3.1
5.4 medium
EPSS
<1%p33
Published
()
Modified
Description

In versions 3.0.0-3.5.0, 2.0.0-2.9.0, and 1.0.1, when users run the command displayed in NGINX Controller user interface (UI) to fetch the agent installer, the server TLS certificate is not verified.

Vendors
f5
Products
nginx controller
Weakness
CWE-295
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.