CVE-2024-7646: [kubernetes] CVE-2024-7646: Ingss-nginx Annotation Validation Bypass
A security issue was discovered in ingress-nginx where an actor with permission to create Ingress objects (in the networking.k8s.io or extensions API group) can bypass annotation validation to inject arbitrary commands and obtain the credentials of the ingress-nginx controller. In the default configuration, that credential has access to all secrets in the cluster.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-7646?
CVE-2024-7646 has been classified as a critical vulnerability due to its potential to allow unauthorized access to sensitive credentials.
How do I fix CVE-2024-7646?
To mitigate CVE-2024-7646, ensure that proper role-based access controls are implemented to restrict unauthorized permissions for creating Ingress objects.
What are the potential impacts of CVE-2024-7646?
CVE-2024-7646 can allow an attacker to inject arbitrary commands, leading to the exposure of sensitive information from the ingress-nginx controller.
Which versions of ingress-nginx are affected by CVE-2024-7646?
CVE-2024-7646 affects all versions of ingress-nginx that allow creation of Ingress objects without proper validation.
Is there a known exploit for CVE-2024-7646?
As of now, there have been no public reports of active exploits targeting CVE-2024-7646.