CVE-2020-5894: High severity f5 nginx controller api management vulnerability
Published May 7, 2020
·Updated
On versions 3.0.0-3.3.0, the NGINX Controller webserver does not invalidate the server-side session token after users log out.
Affected Software
1 affected component
F5 Nginx Controller>=3.0.0<=3.3.0
Event History
May 7, 2020
CVE Published
via MITRE·12:25 PM
Data Sourced
via MITRE·12:25 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID of this issue?
The vulnerability ID of this issue is CVE-2020-5894.
2
What is the severity level of CVE-2020-5894?
CVE-2020-5894 has a severity level of 8.1 (high).
3
Which software versions are affected by CVE-2020-5894?
Versions 3.0.0-3.3.0 of the NGINX Controller webserver are affected by CVE-2020-5894.
4
What is the impact of CVE-2020-5894?
CVE-2020-5894 allows an attacker to potentially retain unauthorized access to a user's account even after logging out from the NGINX Controller webserver.
5
Is there a fix available for CVE-2020-5894?
Yes, a fix for CVE-2020-5894 is available. Please refer to the vendor's advisory for detailed instructions on how to apply the fix.