NGINX Controller TLS Certificate Verification Issues by F5 Networks
CVE-2020-5909
5.4MEDIUM
What is CVE-2020-5909?
In specific versions of NGINX Controller, there is a vulnerability that allows users to execute commands through the user interface to fetch an agent installer without proper verification of the server's TLS certificate. This issue may lead to potential security risks as it exposes systems to man-in-the-middle attacks and other security threats, allowing attackers to intercept communication if the certificate is not verified correctly. Organizations using affected versions should take immediate steps to update their systems and ensure secure configurations.
Affected Version(s)
NGINX Controller 3.0.0-3.5.0, 2.0.0-2.9.0, 1.0.1