CVE-2021-23055: Medium severity F5 NGINX Ingress Controller vulnerability
On version 2.x before 2.0.3 and 1.x before 1.12.3, the command line restriction that controls snippet use with NGINX Ingress Controller does not apply to Ingress objects. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-23055?
CVE-2021-23055 is a vulnerability in NGINX Ingress Controller versions before 2.0.3 and 1.x before 1.12.3.
What is the severity of CVE-2021-23055?
The severity of CVE-2021-23055 is medium with a CVSS score of 6.5.
How does CVE-2021-23055 affect software?
CVE-2021-23055 affects NGINX Ingress Controller versions before 2.0.3 and 1.x before 1.12.3.
How can I fix CVE-2021-23055?
To fix CVE-2021-23055, upgrade NGINX Ingress Controller to version 2.0.3 or 1.12.3.
Where can I find more information about CVE-2021-23055?
More information about CVE-2021-23055 can be found at the following link: [https://support.f5.com/csp/article/K01051452](https://support.f5.com/csp/article/K01051452).