VYPR

apk package

chainguard/ingress-nginx-controller

pkg:apk/chainguard/ingress-nginx-controller

Vulnerabilities (29)

  • CVE-2023-5043Oct 25, 2023
    affected < 0fixed 0

    Ingress nginx annotation injection causes arbitrary command execution.

  • CVE-2022-4886Oct 25, 2023
    affected < 0fixed 0

    Ingress-nginx `path` sanitization can be bypassed with `log_format` directive.

  • CVE-2023-44487HigKEVOct 10, 2023
    affected < 1.9.3-r1fixed 1.9.3-r1

    The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.

  • CVE-2021-25748May 24, 2023
    affected < 0fixed 0

    A security issue was discovered in ingress-nginx where a user that can create or update ingress objects can use a newline character to bypass the sanitization of the `spec.rules[].http.paths[].path` field of an Ingress object (in the `networking.k8s.io` or `extensions` API group)

  • CVE-2022-41742Oct 19, 2022
    affected < 0fixed 0

    NGINX Open Source before versions 1.23.2 and 1.22.1, NGINX Open Source Subscription before versions R2 P1 and R1 P1, and NGINX Plus before versions R27 P1 and R26 P1 have a vulnerability in the module ngx_http_mp4_module that might allow a local attacker to cause a worker process

  • CVE-2022-41741Oct 19, 2022
    affected < 0fixed 0

    NGINX Open Source before versions 1.23.2 and 1.22.1, NGINX Open Source Subscription before versions R2 P1 and R1 P1, and NGINX Plus before versions R27 P1 and R26 P1 have a vulnerability in the module ngx_http_mp4_module that might allow a local attacker to corrupt NGINX worker m

  • CVE-2021-25745May 6, 2022
    affected < 0fixed 0

    A security issue was discovered in ingress-nginx where a user that can create or update ingress objects can use the spec.rules[].http.paths[].path field of an Ingress object (in the networking.k8s.io or extensions API group) to obtain the credentials of the ingress-nginx controll

  • CVE-2020-8553Jul 29, 2020
    affected < 0fixed 0

    The Kubernetes ingress-nginx component prior to version 0.28.0 allows a user with the ability to create namespaces and to read and create ingress objects to overwrite the password file of another ingress which uses nginx.ingress.kubernetes.io/auth-type: basic and which has a hyph

  • CVE-2018-1002104Jan 14, 2020
    affected < 0fixed 0

    Versions < 1.5 of the Kubernetes ingress default backend, which handles invalid ingress traffic, exposed prometheus metrics publicly.

Page 2 of 2