Unrated severityNVD Advisory· Published May 6, 2022· Updated Sep 17, 2024
Ingress-nginx directive injection via annotations
CVE-2021-25746
Description
A security issue was discovered in ingress-nginx where a user that can create or update ingress objects can use .metadata.annotations in an Ingress object (in the networking.k8s.io or extensions API group) to obtain the credentials of the ingress-nginx controller. In the default configuration, that credential has access to all secrets in the cluster.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2(expand)+ 1 more
- (no CPE)
- (no CPE)range: unspecified
Patches
Vulnerability mechanics
References
3- github.com/kubernetes/ingress-nginx/issues/8503mitrex_refsource_MISC
- groups.google.com/g/kubernetes-security-announce/c/hv2-SfdqcfQmitrex_refsource_MISC
- security.netapp.com/advisory/ntap-20220609-0006/mitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.