First published: Wed Jul 29 2020(Updated: )
The Kubernetes ingress-nginx component prior to version 0.28.0 allows a user with the ability to create namespaces and to read and create ingress objects to overwrite the password file of another ingress which uses nginx.ingress.kubernetes.io/auth-type: basic and which has a hyphenated namespace or secret name.
Credit: jordan@liggitt.net jordan@liggitt.net
Affected Software | Affected Version | How to fix |
---|---|---|
Kubernetes ingress-nginx | <0.28.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-8553 is a vulnerability in the Kubernetes ingress-nginx component prior to version 0.28.0.
CVE-2020-8553 has a severity score of 5.9 (medium).
CVE-2020-8553 can be exploited by a user with the ability to create namespaces and to read and create ingress objects to overwrite the password file of another ingress.
The Kubernetes ingress-nginx component versions prior to 0.28.0 are affected by CVE-2020-8553.
Yes, the fix for CVE-2020-8553 is to upgrade to version 0.28.0 or later of the Kubernetes ingress-nginx component.