https://seclists.org/oss-sec/2025/q1/243: [kubernetes] Multiple vulnerabilities in ingss-nginx
Published Mar 24, 2025
·Updated
Affected Software
1 affected component
ingress-nginx ingress-nginx<1.11.0, >=1.11.0<=1.11.4
Frequently Asked Questions
1
What is the severity of CVE-2025-XXXX in ingress-nginx?
The severity of CVE-2025-XXXX is critical due to the potential for arbitrary code execution.
2
How do I fix CVE-2025-XXXX in ingress-nginx?
To fix CVE-2025-XXXX, update ingress-nginx to the latest patched version as recommended by the maintainers.
3
What specific risks are associated with CVE-2025-XXXX in ingress-nginx?
CVE-2025-XXXX can lead to arbitrary code execution and unauthorized disclosure of Secrets accessible to the ingress-nginx controller.
4
Is my ingress-nginx deployment vulnerable to CVE-2025-XXXX?
If you are using an unpatched version of ingress-nginx, your deployment is vulnerable to CVE-2025-XXXX.
5
What are the impacts of exploiting CVE-2025-XXXX in ingress-nginx?
Exploitation of CVE-2025-XXXX could compromise the integrity and confidentiality of your applications by exposing sensitive Secrets.