Cleartext storage of sensitive information in NGINX Controller - CVE-2021-23019

 

Cleartext storage of sensitive information in NGINX Controller - CVE-2021-23019

Published: May 25, 2021


Vulnerability identifier: #VU53575
CSH Severity: High
CVSS v4: 9 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H]
CVE-ID: CVE-2021-23019
CWE-ID: CWE-312
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain access to sensitive information.

The vulnerability exists due to the NGINX Controller Administrator password is exposed via the
systemd.txt file that is included in the NGINX support package. An attacker, who can obtain the support package can retrieve administrator's password and gain unauthorized access to the system.


Affected software

NGINX Controller
IBM Cloud Pak for Business Automation

How to mitigate CVE-2021-23019

Install updates from vendor's website.

NGINX Controller - update to 3.15.0
IBM Cloud Pak for Business Automation - update to 22.0.1.1

External References

Related Security Bulletins