Insecure API Key Generation in NAAS 3.x by F5 Networks
CVE-2021-23020
5.5MEDIUM
What is CVE-2021-23020?
The NAAS 3.x versions prior to 3.10.0 exhibit a vulnerability where API keys are generated using an insecure pseudo-random string and hashing algorithm. This flaw could lead to predictable keys, potentially allowing unauthorized access and compromising the integrity of applications relying on these API keys.
Affected Version(s)
Nginx Controller “3.x before 3.10.0”