First published: Thu Apr 21 2022(Updated: )
On version 2.x before 2.0.3 and 1.x before 1.12.3, the command line restriction that controls snippet use with NGINX Ingress Controller does not apply to Ingress objects. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Credit: f5sirt@f5.com
Affected Software | Affected Version | How to fix |
---|---|---|
F5 NGINX Ingress Controller | >=1.0.0<1.12.3 | |
F5 NGINX Ingress Controller | >=2.0.0<2.0.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-23055 is a vulnerability in NGINX Ingress Controller versions before 2.0.3 and 1.x before 1.12.3.
The severity of CVE-2021-23055 is medium with a CVSS score of 6.5.
CVE-2021-23055 affects NGINX Ingress Controller versions before 2.0.3 and 1.x before 1.12.3.
To fix CVE-2021-23055, upgrade NGINX Ingress Controller to version 2.0.3 or 1.12.3.
More information about CVE-2021-23055 can be found at the following link: [https://support.f5.com/csp/article/K01051452](https://support.f5.com/csp/article/K01051452).