CVE-2022-4886: Ingress-nginx `path` sanitization can be bypassed with `log_format` directive
Published Oct 25, 2023
·Updated
Ingress-nginx path sanitization can be bypassed with logformat directive.
Affected Software
2 affected componentsFixes available
go/k8s.io/ingress-nginx<1.8.0
1.8.0
Kubernetes ingress-nginx<1.8.0
Event History
Oct 25, 2023
CVE Published
via MITRE·07:18 PM
Data Sourced
via MITRE·07:18 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:15 PM
DescriptionSeverityWeaknessAffected Software
Advisory Published
via GitHub·09:30 PM
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2022-4886.
2
What is the severity of CVE-2022-4886?
The severity of CVE-2022-4886 is high, with a CVSS score of 8.8.
3
Which software is affected by CVE-2022-4886?
Ingress-nginx version up to 1.8.0 in Kubernetes is affected by CVE-2022-4886.
4
How can the `path` sanitization be bypassed in Ingress-nginx?
The `path` sanitization in Ingress-nginx can be bypassed by using the `log_format` directive.
5
Is there a fix for CVE-2022-4886?
Yes, upgrading to a version of Ingress-nginx above 1.8.0 will fix CVE-2022-4886.