F5

Nginx Controller

18 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.09%
  • Veröffentlicht 01.06.2021 13:15:08
  • Zuletzt bearbeitet 21.11.2024 05:51:10

The Nginx Controller 3.x before 3.7.0 agent configuration file /etc/controller-agent/agent.conf is world readable with current permission bits set to 644.

  • EPSS 0.09%
  • Veröffentlicht 01.06.2021 13:15:07
  • Zuletzt bearbeitet 21.11.2024 05:51:09

The NAAS 3.x before 3.10.0 API keys were generated using an insecure pseudo-random string and hashing algorithm which could lead to predictable keys.

  • EPSS 0.06%
  • Veröffentlicht 01.06.2021 13:15:07
  • Zuletzt bearbeitet 21.11.2024 05:51:09

The NGINX Controller 2.0.0 thru 2.9.0 and 3.x before 3.15.0 Administrator password may be exposed in the systemd.txt file that is included in the NGINX support package.

  • EPSS 0.22%
  • Veröffentlicht 01.06.2021 12:15:07
  • Zuletzt bearbeitet 21.11.2024 05:51:09

Intra-cluster communication does not use TLS. The services within the NGINX Controller 3.x before 3.4.0 namespace are using cleartext protocols inside the cluster.

  • EPSS 1.46%
  • Veröffentlicht 11.12.2020 20:15:16
  • Zuletzt bearbeitet 21.11.2024 05:21:42

In versions 3.0.0-3.9.0, 2.0.0-2.9.0, and 1.0.1, the NGINX Controller Agent does not use absolute paths when calling system utilities.

  • EPSS 0.39%
  • Veröffentlicht 02.07.2020 13:15:10
  • Zuletzt bearbeitet 21.11.2024 05:34:48

In versions 3.0.0-3.5.0, 2.0.0-2.9.0, and 1.0.1, the NGINX Controller installer starts the download of Kubernetes packages from an HTTP URL On Debian/Ubuntu system.

  • EPSS 0.36%
  • Veröffentlicht 02.07.2020 13:15:10
  • Zuletzt bearbeitet 21.11.2024 05:34:48

In versions 3.0.0-3.5.0, 2.0.0-2.9.0, and 1.0.1, the Neural Autonomic Transport System (NATS) messaging services in use by the NGINX Controller do not require any form of authentication, so any successful connection would be authorized.

  • EPSS 0.12%
  • Veröffentlicht 02.07.2020 13:15:10
  • Zuletzt bearbeitet 21.11.2024 05:34:48

In versions 3.0.0-3.5.0, 2.0.0-2.9.0, and 1.0.1, when users run the command displayed in NGINX Controller user interface (UI) to fetch the agent installer, the server TLS certificate is not verified.

  • EPSS 0.88%
  • Veröffentlicht 01.07.2020 15:15:15
  • Zuletzt bearbeitet 21.11.2024 05:34:47

In NGINX Controller 3.3.0-3.4.0, undisclosed API endpoints may allow for a reflected Cross Site Scripting (XSS) attack. If the victim user is logged in as admin this could result in a complete compromise of the system.

  • EPSS 0.04%
  • Veröffentlicht 01.07.2020 15:15:15
  • Zuletzt bearbeitet 21.11.2024 05:34:47

In NGINX Controller 3.0.0-3.4.0, recovery code required to change a user's password is transmitted and stored in the database in plain text, which allows an attacker who can intercept the database connection or have read access to the database, to re...