CVE-2020-8553
MEDIUMKubernetes ingress-nginx <0.28.0 - Privilege Escalation
Title source: llmDescription
The Kubernetes ingress-nginx component prior to version 0.28.0 allows a user with the ability to create namespaces and to read and create ingress objects to overwrite the password file of another ingress which uses nginx.ingress.kubernetes.io/auth-type: basic and which has a hyphenated namespace or secret name.
Scores
CVSS v3
5.9
EPSS
0.0052
EPSS Percentile
66.5%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N
Classification
CWE
CWE-610
CWE-73
Status
published
Affected Products (2)
kubernetes/ingress-nginx
< 0.28.0
k8s.io/ingress-nginx
< 0.28.0Go
Timeline
Published
Jul 29, 2020
Tracked Since
Feb 18, 2026