Kubernetes Vulnerabilities and Affected Products
Vulnerabilities associated with Kubernetes ingress-nginx.
Products
Clear product- Kubernetes51 vulnerabilities
- ingress-nginx17 vulnerabilities
- kubelet7 vulnerabilities
- Kubernetes ingress-nginx4 vulnerabilities
- Image Builder3 vulnerabilities
- minikube3 vulnerabilities
- image_builder2 vulnerabilities
- kube-apiserver2 vulnerabilities
- Kubernetes Java Client2 vulnerabilities
- Kubernetes Secrets Store CSI Driver2 vulnerabilities
- apiserver1 vulnerability
- argo-cd1 vulnerability
- aws-iam-authenticator1 vulnerability
- azure-file-csi-driver1 vulnerability
- CSI Driver for NFS1 vulnerability
- CSI Snapshotter1 vulnerability
- csi-proxy1 vulnerability
- devtron1 vulnerability
- k8s.gcr.io/defaultbackend1 vulnerability
- kops1 vulnerability
- Kubernetes CSharp Client1 vulnerability
- kubernetes-client/java1 vulnerability
- kubernetes-csi external-provisioner1 vulnerability
- kubernetes-csi external-resizer1 vulnerability
- kubernetes-csi external-snapshotter1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2021-25748HIGH | Ingress-nginx `path` sanitization can be bypassed with newline characterA security issue was discovered in ingress-nginx where a user that can create or update ingress objects can use a newline character to bypass the sanitization of the `spec.rules[].http.paths[].path` field of an Ingress object (in the `networking.k8s.io` or `extensions` API group) to obtain the credentials of the ingress-nginx controller. In the default configuration, that credential has access to all secrets in the cluster. CWE-20May 24, 2023 | CVSS7.6v3.1 | EPSS0.694% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-25746HIGH | Ingress-nginx directive injection via annotationsA security issue was discovered in ingress-nginx where a user that can create or update ingress objects can use .metadata.annotations in an Ingress object (in the networking.k8s.io or extensions API group) to obtain the credentials of the ingress-nginx controller. In the default configuration, that credential has access to all secrets in the cluster. CWE-20May 6, 2022 | CVSS7.6v3.1 | EPSS1.45% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-25745HIGH | Ingress-nginx path can be pointed to service account token fileA security issue was discovered in ingress-nginx where a user that can create or update ingress objects can use the spec.rules[].http.paths[].path field of an Ingress object (in the networking.k8s.io or extensions API group) to obtain the credentials of the ingress-nginx controller. In the default configuration, that credential has access to all secrets in the cluster. CWE-20May 6, 2022 | CVSS7.6v3.1 | EPSS1.16% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-25742HIGH | Ingress-nginx custom snippets allows retrieval of ingress-nginx serviceaccount token and secrets across all namespacesA security issue was discovered in ingress-nginx where a user that can create or update ingress objects can use the custom snippets feature to obtain all secrets in the cluster. CWE-20Oct 29, 2021 | CVSS7.6v3.1 | EPSS1.78% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |