In versions 3.0.0-3.4.0, 2.0.0-2.9.0, and 1.0.1, there is insufficient cross-site request forgery (CSRF) protections for the NGINX Controller user interface.
2020-07-01T14:15:14.513
2024-11-21T05:34:47.533
Modified
CVSSv3.1: 8.8 (HIGH)
AV:N/AC:M/Au:N/C:P/I:P/A:P
8.6
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | f5 | nginx_controller | ≤ 2.9.0 | Yes |
Application | f5 | nginx_controller | ≤ 3.4.0 | Yes |
Application | f5 | nginx_controller | 1.0.1 | Yes |