Improper Authorization in NGINX Controller - CVE-2020-5863
Published: March 20, 2020 / Updated: April 24, 2020
NGINX Controller
Detailed vulnerability description
The vulnerability allows a remote attacker to perform a denial of service attack.
The vulnerability exists due to NGINX Controller allows a remote unauthenticated attacker to create unprivileged user accounts and upload a new license to the system. A remote attacker can use this behavior to consume all available disk space on the system and perform a denial of service attack.