CVE-2018-1002104: Input Validation
Versions < 1.5 of the Kubernetes ingress default backend, which handles invalid ingress traffic, exposed prometheus metrics publicly.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2018-1002104?
CVE-2018-1002104 is a vulnerability in versions < 1.5 of the Kubernetes ingress default backend which exposes prometheus metrics publicly.
How severe is CVE-2018-1002104?
CVE-2018-1002104 has a severity value of 5.3 (medium).
Which software versions are affected by CVE-2018-1002104?
Versions < 1.5 of the Kubernetes ingress default backend, as well as Kubernetes Nginx Ingress Controller up to version 1.5.0, are affected by CVE-2018-1002104.
How can I fix CVE-2018-1002104?
To fix CVE-2018-1002104, update your Kubernetes ingress default backend or Kubernetes Nginx Ingress Controller to version 1.5 or above.
Where can I find more information about CVE-2018-1002104?
You can find more information about CVE-2018-1002104 on the NIST National Vulnerability Database (NVD) website: https://nvd.nist.gov/vuln/detail/CVE-2018-1002104