In versions prior to 3.3.0, the NGINX Controller Agent installer script 'install.sh' uses HTTP instead of HTTPS to check and install packages
The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.
Link | Tags |
---|---|
https://support.f5.com/csp/article/K00958787 | vendor advisory |
https://security.netapp.com/advisory/ntap-20200430-0005/ | third party advisory |