Show filters
17 Total Results
Displaying 11-17 of 17
Sort by:
Attacker Value
Unknown
CVE-2021-25748
Disclosure Date: June 10, 2022 (last updated October 08, 2023)
A security issue was discovered in ingress-nginx where a user that can create or update ingress objects can use a newline character to bypass the sanitization of the `spec.rules[].http.paths[].path` field of an Ingress object (in the `networking.k8s.io` or `extensions` API group) to obtain the credentials of the ingress-nginx controller. In the default configuration, that credential has access to all secrets in the cluster.
0
Attacker Value
Unknown
CVE-2021-25746
Disclosure Date: April 22, 2022 (last updated October 07, 2023)
A security issue was discovered in ingress-nginx where a user that can create or update ingress objects can use .metadata.annotations in an Ingress object (in the networking.k8s.io or extensions API group) to obtain the credentials of the ingress-nginx controller. In the default configuration, that credential has access to all secrets in the cluster.
0
Attacker Value
Unknown
CVE-2021-25745
Disclosure Date: April 22, 2022 (last updated October 07, 2023)
A security issue was discovered in ingress-nginx where a user that can create or update ingress objects can use the spec.rules[].http.paths[].path field of an Ingress object (in the networking.k8s.io or extensions API group) to obtain the credentials of the ingress-nginx controller. In the default configuration, that credential has access to all secrets in the cluster.
0
Attacker Value
Unknown
CVE-2021-23055
Disclosure Date: April 21, 2022 (last updated October 07, 2023)
On version 2.x before 2.0.3 and 1.x before 1.12.3, the command line restriction that controls snippet use with NGINX Ingress Controller does not apply to Ingress objects. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
0
Attacker Value
Unknown
CVE-2021-25742
Disclosure Date: October 29, 2021 (last updated November 28, 2024)
A security issue was discovered in ingress-nginx where a user that can create or update ingress objects can use the custom snippets feature to obtain all secrets in the cluster.
0
Attacker Value
Unknown
CVE-2020-8553
Disclosure Date: July 29, 2020 (last updated February 21, 2025)
The Kubernetes ingress-nginx component prior to version 0.28.0 allows a user with the ability to create namespaces and to read and create ingress objects to overwrite the password file of another ingress which uses nginx.ingress.kubernetes.io/auth-type: basic and which has a hyphenated namespace or secret name.
0
Attacker Value
Unknown
CVE-2018-1002104
Disclosure Date: January 14, 2020 (last updated February 21, 2025)
Versions < 1.5 of the Kubernetes ingress default backend, which handles invalid ingress traffic, exposed prometheus metrics publicly.
0