First published: Thu Apr 23 2020(Updated: )
In versions prior to 3.3.0, the NGINX Controller Agent installer script 'install.sh' uses HTTP instead of HTTPS to check and install packages
Credit: f5sirt@f5.com
Affected Software | Affected Version | How to fix |
---|---|---|
F5 Nginx Controller | >=2.0.0<=2.9.0 | |
F5 Nginx Controller | >=3.0.0<3.3.0 | |
F5 Nginx Controller | =1.0.1 | |
Netapp Cloud Backup |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-5867 is classified as a medium severity vulnerability due to its potential exploitation risks.
To fix CVE-2020-5867, upgrade the NGINX Controller to version 3.3.0 or later.
CVE-2020-5867 affects F5 NGINX Controller versions prior to 3.3.0 and specifically versions from 2.0.0 to 2.9.0 and 1.0.1.
CVE-2020-5867 poses a risk of man-in-the-middle attacks due to the use of HTTP for package installation.
Yes, CVE-2020-5867 can be exploited remotely if an attacker can intercept network traffic during the package installation process.