Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2020-5863

Опубликовано: 27 мар. 2020
Источник: nvd
CVSS3: 8.6
CVSS2: 7.5
EPSS Низкий

Описание

In NGINX Controller versions prior to 3.2.0, an unauthenticated attacker with network access to the Controller API can create unprivileged user accounts. The user which is created is only able to upload a new license to the system but cannot view or modify any other components of the system.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:f5:nginx_controller:*:*:*:*:*:*:*:*
Версия от 2.0.0 (включая) до 2.9.0 (включая)
cpe:2.3:a:f5:nginx_controller:*:*:*:*:*:*:*:*
Версия от 3.0.0 (включая) до 3.2.0 (исключая)
cpe:2.3:a:f5:nginx_controller:1.0.1:*:*:*:*:*:*:*
Конфигурация 2
cpe:2.3:a:netapp:cloud_backup:-:*:*:*:*:*:*:*

EPSS

Процентиль: 78%
0.01111
Низкий

8.6 High

CVSS3

7.5 High

CVSS2

Дефекты

NVD-CWE-noinfo

Связанные уязвимости

CVSS3: 8.6
github
больше 3 лет назад

In NGINX Controller versions prior to 3.2.0, an unauthenticated attacker with network access to the Controller API can create unprivileged user accounts. The user which is created is only able to upload a new license to the system but cannot view or modify any other components of the system.

EPSS

Процентиль: 78%
0.01111
Низкий

8.6 High

CVSS3

7.5 High

CVSS2

Дефекты

NVD-CWE-noinfo