PT-2020-18807 · Nginx · Nginx Controller

Published

2020-07-02

·

Updated

2020-07-08

·

CVE-2020-5909

CVSS v2.0

5.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions NGINX Controller versions 1.0.1 NGINX Controller versions 2.0.0 through 2.9.0 NGINX Controller versions 3.0.0 through 3.5.0
Description The issue arises when users run a command displayed in the NGINX Controller user interface to fetch the agent installer, resulting in the server TLS certificate not being verified.
Recommendations For version 1.0.1, update to a version that verifies the server TLS certificate. For versions 2.0.0 through 2.9.0, update to a version that verifies the server TLS certificate. For versions 3.0.0 through 3.5.0, update to a version that verifies the server TLS certificate.

Fix

Improper Certificate Validation

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-5909

Affected Products

Nginx Controller