PT-2020-18807 · Nginx · Nginx Controller
Published
2020-07-02
·
Updated
2020-07-08
·
CVE-2020-5909
CVSS v2.0
5.8
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
NGINX Controller versions 1.0.1
NGINX Controller versions 2.0.0 through 2.9.0
NGINX Controller versions 3.0.0 through 3.5.0
Description
The issue arises when users run a command displayed in the NGINX Controller user interface to fetch the agent installer, resulting in the server TLS certificate not being verified.
Recommendations
For version 1.0.1, update to a version that verifies the server TLS certificate.
For versions 2.0.0 through 2.9.0, update to a version that verifies the server TLS certificate.
For versions 3.0.0 through 3.5.0, update to a version that verifies the server TLS certificate.
Fix
Improper Certificate Validation
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Nginx Controller