CVE-2021-23055
CVE-2021-23055 is a medium-severity vulnerability in F5 Nginx Ingress Controller with a CVSS 3.x base score of 6.5. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-732.
Key facts
- Severity: Medium (CVSS 3.x base score 6.5)
- CVSS v2: 4.0
- EPSS exploit prediction: 1% (54th percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-732
- Affected product: F5 Nginx Ingress Controller
- Published:
- Last modified:
Description
On version 2.x before 2.0.3 and 1.x before 1.12.3, the command line restriction that controls snippet use with NGINX Ingress Controller does not apply to Ingress objects. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Frequently asked questions
- What is CVE-2021-23055?
- On version 2.x before 2.0.3 and 1.x before 1.12.3, the command line restriction that controls snippet use with NGINX Ingress Controller does not apply to Ingress objects. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
- How severe is CVE-2021-23055?
- CVE-2021-23055 has a CVSS 3.x base score of 6.5, rated medium severity. It is exploitable over network with low attack complexity, requires low privileges and no user interaction. Impact on confidentiality is high, integrity none, and availability none.
- Is CVE-2021-23055 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 1% (54th percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2021-23055?
- CVE-2021-23055 affects F5 Nginx Ingress Controller. See the affected-products list for the exact vulnerable versions.
- How do I fix CVE-2021-23055?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround.
- When was CVE-2021-23055 published?
- CVE-2021-23055 was published on 2022-04-21 and last updated on 2026-06-17.
References
Affected products (1)
- cpe:2.3:a:f5:nginx_ingress_controller:*:*:*:*:*:*:*:*
More vulnerabilities in F5 Nginx Ingress Controller
- CVE-2026-55723 — High (CVSS 8.3): When NGINX Ingress Controller is configured with Custom Resource Definitions (CRDs) or Ingress annotations, an…
- CVE-2025-14727 — High (CVSS 8.3): A vulnerability exists in NGINX Ingress Controller's nginx.org/rewrite-target annotation validation. Note: Software…
- CVE-2026-60005 — High (CVSS 8.2): NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_slice_module module. When the slice directive…
- CVE-2026-42533 — High (CVSS 8.1): A vulnerability exists in NGINX Plus and NGINX Open Source when a map directive uses regex matching and a string…
- CVE-2026-42530 — High (CVSS 8.1): NGINX Open Source has a vulnerability in the ngx_http_v3_module module. When NGINX Open Source is configured to use…
- CVE-2026-42055 — High (CVSS 8.1): NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_proxy_v2_module and…
All CVEs affecting F5 Nginx Ingress Controller →
Other CWE-732 (Incorrect Permission Assignment for Critical Resource) vulnerabilities
- CVE-2026-92941 — Critical (CVSS 10.0): vm2 versions from 3.11.3 before 3.11.7 expose the host tls module to NodeVM sandbox code, allowing attackers to call…
- CVE-2026-87988 — Critical (CVSS 10.0): An arbitrary file access vulnerability in Mistral Vibe allows an attacker to bypass workspace restrictions through…
- CVE-2026-9508 — Critical (CVSS 10.0): Incorrect permission settings on a critical resource in Suprema BioStar 2 (versions 2.9.3 through 2.9.11) that allow…
- CVE-2025-14988 — Critical (CVSS 10.0): A security issue has been identified in ibaPDA that could allow unauthorized actions on the file system under certain…
- CVE-2025-69426 — Critical (CVSS 10.0): The Ruckus vRIoT IoT Controller firmware versions prior to 3.0.0.0 (GA) contain hardcoded credentials for an operating…
- CVE-2025-12004 — Critical (CVSS 10.0): Incorrect Permission Assignment for Critical Resource vulnerability in The Wikimedia Foundation Mediawiki - Lockdown…
Browse all CWE-732 (Incorrect Permission Assignment for Critical Resource) vulnerabilities →