CVE-2021-25746: Ingress-nginx directive injection via annotations
A security issue was discovered in ingress-nginx where a user that can create or update ingress objects can use .metadata.annotations in an Ingress object (in the networking.k8s.io or extensions API group) to obtain the credentials of the ingress-nginx controller. In the default configuration, that credential has access to all secrets in the cluster.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-25746?
CVE-2021-25746 is a security issue discovered in ingress-nginx that allows a user to obtain the credentials of the ingress-nginx controller.
How does CVE-2021-25746 impact Kubernetes ingress-nginx?
CVE-2021-25746 allows a user that can create or update ingress objects to access the credentials of the ingress-nginx controller.
What is the severity of CVE-2021-25746?
CVE-2021-25746 has a severity rating of 7.1 (high).
How can I fix CVE-2021-25746 in Kubernetes ingress-nginx?
To fix CVE-2021-25746, update ingress-nginx to a version higher than 1.2.0.
Where can I find more information about CVE-2021-25746?
More information about CVE-2021-25746 can be found in the references provided: [link 1], [link 2], [link 3].