CVE-2020-27730: Path Traversal
Published Dec 11, 2020
·Updated
In versions 3.0.0-3.9.0, 2.0.0-2.9.0, and 1.0.1, the NGINX Controller Agent does not use absolute paths when calling system utilities.
Affected Software
4 affected components
F5 Nginx Controller>=2.0.0<=2.9.0
F5 Nginx Controller>=3.0.0<3.10.0
F5 Nginx Controller=1.0.1
NetApp Cloud Backup
Event History
Dec 11, 2020
CVE Published
via MITRE·07:03 PM
Data Sourced
via MITRE·07:03 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2020-27730.
2
What is the severity of CVE-2020-27730?
The severity of CVE-2020-27730 is critical, with a severity value of 9.8.
3
Which software is affected by CVE-2020-27730?
The affected software includes F5 Nginx Controller versions 1.0.1, 2.0.0-2.9.0, and 3.0.0-3.9.0, as well as Netapp Cloud Backup.
4
What is the description of CVE-2020-27730?
In versions 3.0.0-3.9.0, 2.0.0-2.9.0, and 1.0.1, the NGINX Controller Agent does not use absolute paths when calling system utilities.
5
Are there any references for CVE-2020-27730?
Yes, you can find references for CVE-2020-27730 at the following URLs: [Netapp Security Advisory](https://security.netapp.com/advisory/ntap-20210115-0004/) and [F5 Support Article](https://support.f5.com/csp/article/K43530108).