CVE Database
/

CVE-2020-5863

Back to search

CVE-2020-5863

Published: Mar 27, 2020

Modified: Aug 4, 2024

PUBLISHED

Description

In NGINX Controller versions prior to 3.2.0, an unauthenticated attacker with network access to the Controller API can create unprivileged user accounts. The user which is created is only able to upload a new license to the system but cannot view or modify any other components of the system.

VendorProductVersions

n/a

NGINX Controller

affected
3.0.0-3.1.0, 2.0.0-2.9.0, 1.0.1

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now