F5 NGINX Controller 3.6.0

CPE Details

F5 NGINX Controller 3.6.0
3.6.0
2020-07-06
15h18 +00:00
2020-07-06
15h18 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:f5:nginx_controller:3.6.0:*:*:*:*:*:*:*

Informations

Vendor

f5

Product

nginx_controller

Version

3.6.0

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2021-23021 2021-06-01 10h23 +00:00 The Nginx Controller 3.x before 3.7.0 agent configuration file /etc/controller-agent/agent.conf is world readable with current permission bits set to 644.
5.5
Medium
CVE-2021-23020 2021-06-01 10h14 +00:00 The NAAS 3.x before 3.10.0 API keys were generated using an insecure pseudo-random string and hashing algorithm which could lead to predictable keys.
5.5
Medium
CVE-2021-23019 2021-06-01 10h03 +00:00 The NGINX Controller 2.0.0 thru 2.9.0 and 3.x before 3.15.0 Administrator password may be exposed in the systemd.txt file that is included in the NGINX support package.
7.8
High
CVE-2020-27730 2020-12-11 18h03 +00:00 In versions 3.0.0-3.9.0, 2.0.0-2.9.0, and 1.0.1, the NGINX Controller Agent does not use absolute paths when calling system utilities.
9.8
Critical