CVE-2021-23055

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
21/04/2022
Last modified:
30/08/2022

Description

On version 2.x before 2.0.3 and 1.x before 1.12.3, the command line restriction that controls snippet use with NGINX Ingress Controller does not apply to Ingress objects. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:f5:nginx_ingress_controller:*:*:*:*:*:*:*:* 1.0.0 (including) 1.12.3 (excluding)
cpe:2.3:a:f5:nginx_ingress_controller:*:*:*:*:*:*:*:* 2.0.0 (including) 2.0.3 (excluding)


References to Advisories, Solutions, and Tools