cbcvebase.
CVE-2020-5864
published 2020-04-23

CVE-2020-5864: In versions of NGINX Controller prior to 3.2.0, communication between NGINX Controller and NGINX Plus instances skip TLS verification by default.

high7.4CVSS 3.1
AVNACHPRNUINSUCHIHAN
In versions of NGINX Controller prior to 3.2.0, communication between NGINX Controller and NGINX Plus instances skip TLS verification by default.

Affected

6 ranges
VendorProductVersion rangeFixed in
f5nginx_controller< 3.2.03.2.0
f5nginx_controller
f5nginx_controller
f5nginx_controller2.0.0 – 2.9.0
f5nginx_controller>= 3.0.0 < 3.3.03.3.0
f5nginx_plus