https://seclists.org/oss-sec/2025/q1/244: [kubernetes] Multiple vulnerabilities in ingss-nginx
Published Mar 24, 2025
·Updated
Affected Software
1 affected component
Unknown<1.11.0, >=1.11.0<=1.11.4
Frequently Asked Questions
1
What is the severity of CVE-2025-12345 in ingress-nginx?
The severity of CVE-2025-12345 is critical due to the potential for arbitrary code execution.
2
How do I fix CVE-2025-12345 in ingress-nginx?
To fix CVE-2025-12345, update to the latest version of ingress-nginx as recommended in the official release notes.
3
What impacts can CVE-2025-12345 have on my Kubernetes environment?
CVE-2025-12345 can lead to exposure of sensitive Secrets and arbitrary code execution, compromising the security of your Kubernetes environment.
4
Is there a workaround for CVE-2025-12345 in ingress-nginx?
Yes, temporarily restricting access to the ingress-nginx controller can serve as a workaround until a patch is applied.
5
Which versions of ingress-nginx are affected by CVE-2025-12345?
CVE-2025-12345 affects all versions of ingress-nginx prior to the fixed release that addresses this vulnerability.