CVE-2022-23008: XSS
On NGINX Controller API Management versions 3.18.0-3.19.0, an authenticated attacker with access to the "user" or "admin" role can use undisclosed API endpoints on NGINX Controller API Management to inject JavaScript code that is executed on managed NGINX data plane instances. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-23008?
CVE-2022-23008 is rated as a medium severity vulnerability due to the potential for JavaScript injection by authenticated users.
Who is affected by CVE-2022-23008?
CVE-2022-23008 affects users of NGINX Controller API Management versions 3.18.0 to 3.19.0.
How do I fix CVE-2022-23008?
To fix CVE-2022-23008, upgrade to NGINX Controller API Management version 3.19.1 or later.
What does CVE-2022-23008 exploit?
CVE-2022-23008 exploits undisclosed API endpoints to allow authenticated attackers to inject JavaScript code.
What roles are involved in CVE-2022-23008?
CVE-2022-23008 involves authenticated users with either 'user' or 'admin' roles being able to exploit the vulnerability.