Unrated severityNVD Advisory· Published Oct 29, 2021· Updated Sep 16, 2024
Ingress-nginx custom snippets allows retrieval of ingress-nginx serviceaccount token and secrets across all namespaces
CVE-2021-25742
Description
A security issue was discovered in ingress-nginx where a user that can create or update ingress objects can use the custom snippets feature to obtain all secrets in the cluster.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2- Range: unspecified
Patches
Vulnerability mechanics
References
3- github.com/kubernetes/ingress-nginx/issues/7837mitrex_refsource_MISC
- groups.google.com/g/kubernetes-security-announce/c/mT4JJxi9tQYmitrex_refsource_MISC
- security.netapp.com/advisory/ntap-20211203-0001/mitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.