First published: Fri Apr 22 2022(Updated: )
A security issue was discovered in ingress-nginx where a user that can create or update ingress objects can use .metadata.annotations in an Ingress object (in the networking.k8s.io or extensions API group) to obtain the credentials of the ingress-nginx controller. In the default configuration, that credential has access to all secrets in the cluster.
Credit: jordan@liggitt.net
Affected Software | Affected Version | How to fix |
---|---|---|
Kubernetes ingress-nginx | <1.2.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-25746 is a security issue discovered in ingress-nginx that allows a user to obtain the credentials of the ingress-nginx controller.
CVE-2021-25746 allows a user that can create or update ingress objects to access the credentials of the ingress-nginx controller.
CVE-2021-25746 has a severity rating of 7.1 (high).
To fix CVE-2021-25746, update ingress-nginx to a version higher than 1.2.0.
More information about CVE-2021-25746 can be found in the references provided: [link 1], [link 2], [link 3].