NGINX Controller Agent Installer Script Vulnerability in F5 Networks
CVE-2020-5867
8.1HIGH
What is CVE-2020-5867?
The NGINX Controller Agent installer script, 'install.sh', prior to version 3.3.0 utilizes HTTP instead of HTTPS for package checking and installation. This oversight allows potential attackers to intercept and manipulate the installation process, leading to security risks such as data integrity issues and unauthorized access to system resources. Users are encouraged to upgrade to the latest version to mitigate this vulnerability and ensure secure package management.
Affected Version(s)
NGINX Controller < 3.3.0