CVE-2020-5901: XSS
Published Jul 1, 2020
·Updated
In NGINX Controller 3.3.0-3.4.0, undisclosed API endpoints may allow for a reflected Cross Site Scripting (XSS) attack. If the victim user is logged in as admin this could result in a complete compromise of the system.
Affected Software
1 affected component
F5 Nginx Controller>=3.3.0<=3.4.0
Event History
Jul 1, 2020
CVE Published
via MITRE·02:03 PM
Data Sourced
via MITRE·02:03 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2020-5901?
The severity of CVE-2020-5901 is critical with a CVSS score of 9.6.
2
How can I mitigate CVE-2020-5901?
To mitigate CVE-2020-5901, consider upgrading NGINX Controller to versions 3.5.1 or later.
3
What is the description of CVE-2020-5901?
CVE-2020-5901 involves undisclosed API endpoints in NGINX Controller 3.3.0-3.4.0 that may allow for a reflected Cross Site Scripting (XSS) attack.