CVE-2020-27730

Severity CVSS v4.0:
Pending analysis
Type:
CWE-22 Path Traversal
Publication date:
11/12/2020
Last modified:
06/08/2022

Description

In versions 3.0.0-3.9.0, 2.0.0-2.9.0, and 1.0.1, the NGINX Controller Agent does not use absolute paths when calling system utilities.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:f5:nginx_controller:*:*:*:*:*:*:*:* 2.0.0 (including) 2.9.0 (including)
cpe:2.3:a:f5:nginx_controller:*:*:*:*:*:*:*:* 3.0.0 (including) 3.10.0 (excluding)
cpe:2.3:a:f5:nginx_controller:1.0.1:*:*:*:*:*:*:*
cpe:2.3:a:netapp:cloud_backup:-:*:*:*:*:*:*:*