CVE-2018-5543

Severity CVSS v4.0:
Pending analysis
Type:
CWE-522 Insufficiently Protected Credentials
Publication date:
31/07/2018
Last modified:
03/10/2019

Description

The F5 BIG-IP Controller for Kubernetes 1.0.0-1.5.0 (k8s-bigip-crtl) passes BIG-IP username and password as command line parameters, which may lead to disclosure of the credentials used by the container.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:f5:big-ip_controller:*:*:*:*:*:kubernetes:*:* 1.0.0 (including) 1.5.0 (including)