High severity7.6NVD Advisory· Published May 6, 2022· Updated Jun 17, 2026
CVE-2021-25746
CVE-2021-25746
Description
A security issue was discovered in ingress-nginx where a user that can create or update ingress objects can use .metadata.annotations in an Ingress object (in the networking.k8s.io or extensions API group) to obtain the credentials of the ingress-nginx controller. In the default configuration, that credential has access to all secrets in the cluster.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3cpe:2.3:a:kubernetes:ingress-nginx:*:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:kubernetes:ingress-nginx:*:*:*:*:*:*:*:*range: <1.2.0
- (no CPE)
- (no CPE)range: unspecified
Patches
Vulnerability mechanics
References
3- github.com/kubernetes/ingress-nginx/issues/8503nvdIssue TrackingMitigationThird Party Advisory
- groups.google.com/g/kubernetes-security-announce/c/hv2-SfdqcfQnvdIssue TrackingMitigationThird Party Advisory
- security.netapp.com/advisory/ntap-20220609-0006/nvdThird Party Advisory
News mentions
0No linked articles in our index yet.