CVEs (3)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1F5 4Nginx Api Connectivity Manager Nginx Ingress ControllerNginx Instance Manager+1 moreJun 17, 2026 Nov 6, 2024 5.1 MEDIUM· v4 5.4 MEDIUM· v3 N/A· v2 A session fixation issue was discovered in the NGINX OpenID Connect reference implementation, where a nonce was not checked at login time. This flaw allows an attacker to fix a victim's session to an attacker-controlled...Show more |
1F5 3Nginx Api Connectivity Manager Nginx Instance ManagerNginx Security MonitoringJun 17, 2026 May 3, 2023 N/A· v4 7.1 HIGH· v3 N/A· v2 NGINX Management Suite default file permissions are set such that an authenticated attacker may be able to modify sensitive files on NGINX Instance Manager and NGINX API Connectivity Manager. Note: Software versions w...Show more |
2F5 Netapp5Cloud Backup Nginx Api Connectivity ManagerNginx Instance Manager+2 moreJun 17, 2026 May 3, 2023 N/A· v4 8.1 HIGH· v3 N/A· v2 NGINX Management Suite may allow an authenticated attacker to gain access to configuration objects outside of their assigned environment. Note: Software versions which have reached End of Technical Support (EoTS) are...Show more |