First published: Thu Apr 23 2020(Updated: )
In versions of NGINX Controller prior to 3.3.0, the helper.sh script, which is used optionally in NGINX Controller to change settings, uses sensitive items as command-line arguments.
Credit: f5sirt@f5.com
Affected Software | Affected Version | How to fix |
---|---|---|
F5 Nginx Controller | >=2.0.0<=2.9.0 | |
F5 Nginx Controller | >=3.0.0<3.3.0 | |
F5 Nginx Controller | =1.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this vulnerability is CVE-2020-5866.
The severity of CVE-2020-5866 is medium, with a severity value of 5.5.
The affected software for CVE-2020-5866 is F5 Nginx Controller versions 2.0.0 to 2.9.0, versions 3.0.0 to 3.3.0, and version 1.0.1.
In versions of NGINX Controller prior to 3.3.0, the helper.sh script, which is used optionally in NGINX Controller to change settings, uses sensitive items as command-line arguments.
To fix CVE-2020-5866, update to NGINX Controller version 3.3.0 or later.