In versions 3.0.0-3.5.0, 2.0.0-2.9.0, and 1.0.1, the Neural Autonomic Transport System (NATS) messaging services in use by the NGINX Controller do not require any form of authentication, so any successful connection would be authorized.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2020-27064 | In versions 3.0.0-3.5.0, 2.0.0-2.9.0, and 1.0.1, the Neural Autonomic Transport System (NATS) messaging services in use by the NGINX Controller do not require any form of authentication, so any successful connection would be authorized. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://support.f5.com/csp/article/K59209532 |
|
History
No history.
Status: PUBLISHED
Assigner: f5
Published:
Updated: 2024-08-04T08:47:40.655Z
Reserved: 2020-01-06T00:00:00
Link: CVE-2020-5910
No data.
Status : Modified
Published: 2020-07-02T13:15:10.373
Modified: 2024-11-21T05:34:48.707
Link: CVE-2020-5910
No data.
OpenCVE Enrichment
No data.
EUVD