cbcvebase.
CVE-2020-27730
published 2020-12-11

CVE-2020-27730: In versions 3.0.0-3.9.0, 2.0.0-2.9.0, and 1.0.1, the NGINX Controller Agent does not use absolute paths when calling system utilities.

critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
In versions 3.0.0-3.9.0, 2.0.0-2.9.0, and 1.0.1, the NGINX Controller Agent does not use absolute paths when calling system utilities.

Affected

5 ranges
VendorProductVersion rangeFixed in
f5nginx_controller
f5nginx_controller
f5nginx_controller
f5nginx_controller2.0.0 – 2.9.0
f5nginx_controller>= 3.0.0 < 3.10.03.10.0