PT-2020-18809 · Canonical+3 · Ubuntu+3
Published
2020-07-02
·
Updated
2020-07-08
·
CVE-2020-5911
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
NGINX Controller versions 1.0.1
NGINX Controller versions 2.0.0 through 2.9.0
NGINX Controller versions 3.0.0 through 3.5.0
Description
The NGINX Controller installer starts the download of Kubernetes packages from an HTTP URL on Debian/Ubuntu systems.
Recommendations
For version 1.0.1, update to a version that downloads Kubernetes packages over a secure connection.
For versions 2.0.0 through 2.9.0, update to a version that downloads Kubernetes packages over a secure connection.
For versions 3.0.0 through 3.5.0, update to a version that downloads Kubernetes packages over a secure connection.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Debian
Kubernetes
Nginx Controller
Ubuntu