CVE-2020-8553

MEDIUM

Kubernetes ingress-nginx <0.28.0 - Privilege Escalation

Title source: llm

Description

The Kubernetes ingress-nginx component prior to version 0.28.0 allows a user with the ability to create namespaces and to read and create ingress objects to overwrite the password file of another ingress which uses nginx.ingress.kubernetes.io/auth-type: basic and which has a hyphenated namespace or secret name.

Scores

CVSS v3 5.9
EPSS 0.0052
EPSS Percentile 66.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N

Classification

CWE
CWE-610 CWE-73
Status published

Affected Products (2)

kubernetes/ingress-nginx < 0.28.0
k8s.io/ingress-nginx < 0.28.0Go

Timeline

Published Jul 29, 2020
Tracked Since Feb 18, 2026