First published: Thu Jul 02 2020(Updated: )
In versions 3.0.0-3.5.0, 2.0.0-2.9.0, and 1.0.1, the Neural Autonomic Transport System (NATS) messaging services in use by the NGINX Controller do not require any form of authentication, so any successful connection would be authorized.
Credit: f5sirt@f5.com
Affected Software | Affected Version | How to fix |
---|---|---|
F5 Nginx Controller | >=2.0.0<=2.9.0 | |
F5 Nginx Controller | >=3.0.0<=3.5.0 | |
F5 Nginx Controller | =1.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.