CVE-2020-5910
https://notcve.org/view.php?id=CVE-2020-5910
In versions 3.0.0-3.5.0, 2.0.0-2.9.0, and 1.0.1, the Neural Autonomic Transport System (NATS) messaging services in use by the NGINX Controller do not require any form of authentication, so any successful connection would be authorized. En las versiones 3.0.0 hasta 3.5.0, 2.0.0 hasta 2.9.0 y 1.0.1, los servicios de mensajería de Neural Autonomic Transport System (NATS) que utiliza NGINX Controller no requieren ninguna forma de autenticación, por lo que cualquier conexión con éxito sería autorizada • https://support.f5.com/csp/article/K59209532 • CWE-306: Missing Authentication for Critical Function •
CVE-2020-5911
https://notcve.org/view.php?id=CVE-2020-5911
In versions 3.0.0-3.5.0, 2.0.0-2.9.0, and 1.0.1, the NGINX Controller installer starts the download of Kubernetes packages from an HTTP URL On Debian/Ubuntu system. En las versiones 3.0.0 hasta 3.5.0, 2.0.0 hasta 2.9.0 y 1.0.1, el NGINX Controller inicia la descarga de los paquetes de Kubernetes desde una URL HTTP en el sistema Debian/Ubuntu • https://support.f5.com/csp/article/K84084843 •
CVE-2020-5900
https://notcve.org/view.php?id=CVE-2020-5900
In versions 3.0.0-3.4.0, 2.0.0-2.9.0, and 1.0.1, there is insufficient cross-site request forgery (CSRF) protections for the NGINX Controller user interface. En las versiones 3.0.0 hasta 3.4.0, 2.0.0 hasta 2.9.0 y 1.0.1, no se presentan suficientes protecciones de cross-site request forgery (CSRF) para la interfaz de usuario de NGINX Controller • https://support.f5.com/csp/article/K31044532 • CWE-352: Cross-Site Request Forgery (CSRF) •
CVE-2020-5867
https://notcve.org/view.php?id=CVE-2020-5867
In versions prior to 3.3.0, the NGINX Controller Agent installer script 'install.sh' uses HTTP instead of HTTPS to check and install packages En versiones anteriores a la versión 3.3.0, el instalador de NGINX Controller Agent "install.sh" usa HTTP en lugar de HTTPS para comprobar e instalar paquetes. • https://security.netapp.com/advisory/ntap-20200430-0005 https://support.f5.com/csp/article/K00958787 • CWE-319: Cleartext Transmission of Sensitive Information CWE-494: Download of Code Without Integrity Check •
CVE-2020-5866
https://notcve.org/view.php?id=CVE-2020-5866
In versions of NGINX Controller prior to 3.3.0, the helper.sh script, which is used optionally in NGINX Controller to change settings, uses sensitive items as command-line arguments. En las versiones de NGINX Controller anteriores a la versión 3.3.0, el script helper.sh, que es usado opcionalmente en NGINX Controller para cambiar la configuración, usa elementos confidenciales como argumentos de línea de comandos. • https://security.netapp.com/advisory/ntap-20200430-0005 https://support.f5.com/csp/article/K11922628 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •