github.com
https://github.com/kubernetes/ingress-nginx/issues/8503 CVE-2021-25746
HIGH
Ingress-nginx directive injection via annotations
Record summary
CVE-2021-25746 has a selected CVSS score of 7.6 (high).
Description
A security issue was discovered in ingress-nginx where a user that can create or update ingress objects can use .metadata.annotations in an Ingress object (in the networking.k8s.io or extensions API group) to obtain the credentials of the ingress-nginx controller. In the default configuration, that credential has access to all secrets in the cluster.
Description source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Kubernetes ingress-nginxBrowse Kubernetes / Kubernetes ingress-nginx | CVE List | Before 1.2.0 | affected |
References
4groups.google.com
https://groups.google.com/g/kubernetes-security-announce/c/hv2-SfdqcfQ nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2021-25746 security.netapp.comConfirmation
https://security.netapp.com/advisory/ntap-20220609-0006