BIT-nginx-ingress-controller-2021-25748

Import Source
https://github.com/bitnami/vulndb/tree/main/data/nginx-ingress-controller/BIT-nginx-ingress-controller-2021-25748.json
Aliases
Published
2024-03-06T10:58:58.103Z
Modified
2024-03-06T11:25:28.861Z
Details

A security issue was discovered in ingress-nginx where a user that can create or update ingress objects can use a newline character to bypass the sanitization of the spec.rules[].http.paths[].path field of an Ingress object (in the networking.k8s.io or extensions API group) to obtain the credentials of the ingress-nginx controller. In the default configuration, that credential has access to all secrets in the cluster.

References

Affected packages

Bitnami / nginx-ingress-controller

Package

Name
nginx-ingress-controller

Affected ranges

Type
SEMVER
Events
Introduced
0The exact introduced commit is unknown
Fixed
1.2.1