CVE-2020-5867

Severity CVSS v4.0:
Pending analysis
Type:
CWE-319 Cleartext Transmission of Sensitive Information
Publication date:
23/04/2020
Last modified:
26/04/2022

Description

In versions prior to 3.3.0, the NGINX Controller Agent installer script 'install.sh' uses HTTP instead of HTTPS to check and install packages

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:f5:nginx_controller:*:*:*:*:*:*:*:* 2.0.0 (including) 2.9.0 (including)
cpe:2.3:a:f5:nginx_controller:*:*:*:*:*:*:*:* 3.0.0 (including) 3.3.0 (excluding)
cpe:2.3:a:f5:nginx_controller:1.0.1:*:*:*:*:*:*:*
cpe:2.3:a:netapp:cloud_backup:-:*:*:*:*:*:*:*