CVE-2020-5900: CSRF
In versions 3.0.0-3.4.0, 2.0.0-2.9.0, and 1.0.1, there is insufficient cross-site request forgery (CSRF) protections for the NGINX Controller user interface.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-5900?
CVE-2020-5900 is a vulnerability in F5 Nginx Controller versions 3.0.0-3.4.0, 2.0.0-2.9.0, and 1.0.1 that allows for insufficient CSRF protections in the NGINX Controller user interface.
What is the severity of CVE-2020-5900?
CVE-2020-5900 has a severity value of 8.8, which is considered high.
How does CVE-2020-5900 affect F5 Nginx Controller?
CVE-2020-5900 affects F5 Nginx Controller versions 3.0.0-3.4.0, 2.0.0-2.9.0, and 1.0.1 by exposing them to insufficient CSRF protections.
How can I fix CVE-2020-5900?
To fix CVE-2020-5900, it is recommended to update to a version of F5 Nginx Controller that includes the necessary CSRF protections.
Where can I find more information about CVE-2020-5900?
More information about CVE-2020-5900 can be found at the following reference: https://support.f5.com/csp/article/K31044532