First published: Fri Dec 11 2020(Updated: )
In versions 3.0.0-3.9.0, 2.0.0-2.9.0, and 1.0.1, the NGINX Controller Agent does not use absolute paths when calling system utilities.
Credit: f5sirt@f5.com
Affected Software | Affected Version | How to fix |
---|---|---|
F5 Nginx Controller | >=2.0.0<=2.9.0 | |
F5 Nginx Controller | >=3.0.0<3.10.0 | |
F5 Nginx Controller | =1.0.1 | |
Netapp Cloud Backup |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2020-27730.
The severity of CVE-2020-27730 is critical, with a severity value of 9.8.
The affected software includes F5 Nginx Controller versions 1.0.1, 2.0.0-2.9.0, and 3.0.0-3.9.0, as well as Netapp Cloud Backup.
In versions 3.0.0-3.9.0, 2.0.0-2.9.0, and 1.0.1, the NGINX Controller Agent does not use absolute paths when calling system utilities.
Yes, you can find references for CVE-2020-27730 at the following URLs: [Netapp Security Advisory](https://security.netapp.com/advisory/ntap-20210115-0004/) and [F5 Support Article](https://support.f5.com/csp/article/K43530108).