CVE-2021-23019

The NGINX Controller 2.0.0 thru 2.9.0 and 3.x before 3.15.0 Administrator password may be exposed in the systemd.txt file that is included in the NGINX support package.
References
Link Resource
https://support.f5.com/csp/article/K04884013 Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:f5:nginx_controller:*:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx_controller:*:*:*:*:*:*:*:*

History

11 Jun 2021, 19:42

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : 6.9
v3 : 7.8
CWE CWE-522
CPE cpe:2.3:a:f5:nginx_controller:*:*:*:*:*:*:*:*
References (MISC) https://support.f5.com/csp/article/K04884013 - (MISC) https://support.f5.com/csp/article/K04884013 - Vendor Advisory

01 Jun 2021, 13:15

Type Values Removed Values Added
New CVE

Information

Published : 2021-06-01 13:15

Updated : 2023-12-10 13:55


NVD link : CVE-2021-23019

Mitre link : CVE-2021-23019

CVE.ORG link : CVE-2021-23019


JSON object : View

Products Affected

f5

  • nginx_controller
CWE
CWE-522

Insufficiently Protected Credentials

CWE-201

Insertion of Sensitive Information Into Sent Data