CVE Vulnerabilities

CVE-2020-5864

Improper Certificate Validation

Published: Apr 23, 2020 | Modified: Apr 30, 2020
CVSS 3.x
7.4
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
CVSS 2.x
5.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu

In versions of NGINX Controller prior to 3.2.0, communication between NGINX Controller and NGINX Plus instances skip TLS verification by default.

Weakness

The product does not validate, or incorrectly validates, a certificate.

Affected Software

Name Vendor Start Version End Version
Nginx_controller F5 2.0.0 (including) 2.9.0 (including)
Nginx_controller F5 3.0.0 (including) 3.3.0 (excluding)
Nginx_controller F5 1.0.1 (including) 1.0.1 (including)

Potential Mitigations

References