In versions prior to 3.3.0, the NGINX Controller is configured to communicate with its Postgres database server over unencrypted channels, making the communicated data vulnerable to interception via man-in-the-middle (MiTM) attacks.
The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Nginx_controller | F5 | 2.0.0 (including) | 2.9.0 (including) |
Nginx_controller | F5 | 3.0.0 (including) | 3.3.0 (excluding) |
Nginx_controller | F5 | 1.0.1 (including) | 1.0.1 (including) |