High severity7.6NVD Advisory· Published Oct 29, 2021· Updated Jun 17, 2026
CVE-2021-25742
CVE-2021-25742
Description
A security issue was discovered in ingress-nginx where a user that can create or update ingress objects can use the custom snippets feature to obtain all secrets in the cluster.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
6cpe:2.3:a:kubernetes:ingress-nginx:*:*:*:*:*:*:*:*+ 3 more
- cpe:2.3:a:kubernetes:ingress-nginx:*:*:*:*:*:*:*:*range: <0.49.1
- cpe:2.3:a:kubernetes:ingress-nginx:1.0.0:*:*:*:*:*:*:*
- (no CPE)
- (no CPE)range: unspecified
Patches
Vulnerability mechanics
References
3- github.com/kubernetes/ingress-nginx/issues/7837nvdExploitIssue TrackingMitigationThird Party Advisory
- groups.google.com/g/kubernetes-security-announce/c/mT4JJxi9tQYnvdMailing ListMitigationThird Party Advisory
- security.netapp.com/advisory/ntap-20211203-0001/nvdThird Party Advisory
News mentions
0No linked articles in our index yet.