CVE-2020-5911: High severity f5 nginx controller api management vulnerability
Published Jul 2, 2020
·Updated
In versions 3.0.0-3.5.0, 2.0.0-2.9.0, and 1.0.1, the NGINX Controller installer starts the download of Kubernetes packages from an HTTP URL On Debian/Ubuntu system.
Affected Software
3 affected components
F5 Nginx Controller>=2.0.0<=2.9.0
F5 Nginx Controller>=3.0.0<=3.5.0
F5 Nginx Controller=1.0.1
Event History
Jul 2, 2020
CVE Published
via MITRE·12:23 PM
Data Sourced
via MITRE·12:23 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2020-5911?
The severity of CVE-2020-5911 is high with a CVSS score of 7.3.
2
How does CVE-2020-5911 affect NGINX Controller installer?
In versions 3.0.0-3.5.0, 2.0.0-2.9.0, and 1.0.1, the NGINX Controller installer starts the download of Kubernetes packages from an HTTP URL on Debian/Ubuntu system.
3
How can I mitigate the vulnerability CVE-2020-5911?
To mitigate CVE-2020-5911, update NGINX Controller to a version that does not download Kubernetes packages from an HTTP URL.