CVE Vulnerabilities

CVE-2020-5909

Improper Certificate Validation

Published: Jul 02, 2020 | Modified: Nov 21, 2024
CVSS 3.x
5.4
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
CVSS 2.x
5.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

In versions 3.0.0-3.5.0, 2.0.0-2.9.0, and 1.0.1, when users run the command displayed in NGINX Controller user interface (UI) to fetch the agent installer, the server TLS certificate is not verified.

Weakness

The product does not validate, or incorrectly validates, a certificate.

Affected Software

NameVendorStart VersionEnd Version
Nginx_controllerF52.0.0 (including)2.9.0 (including)
Nginx_controllerF53.0.0 (including)3.5.0 (including)
Nginx_controllerF51.0.1 (including)1.0.1 (including)

Potential Mitigations

References