In versions of NGINX Controller prior to 3.3.0, the helper.sh script, which is used optionally in NGINX Controller to change settings, uses sensitive items as command-line arguments.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
https://support.f5.com/csp/article/K11922628 | vendor advisory |
https://security.netapp.com/advisory/ntap-20200430-0005/ |