VDB
Sign up
MEDIUM6.5

GHSA-863x-868h-968x

Ingress-nginx `path` sanitization can be bypassed with newline character

Quick fix

GHSA-863x-868h-968x — k8s.io/ingress-nginx: upgrade to the fixed version with the command below.

go get k8s.io/ingress-nginx@v1.2.1

Details

A security issue was discovered in ingress-nginx where a user that can create or update ingress objects can use a newline character to bypass the sanitization of the `spec.rules[].http.paths[].path` field of an Ingress object (in the `networking.k8s.io` or `extensions` API group) to obtain the credentials of the ingress-nginx controller. In the default configuration, that credential has access to all secrets in the cluster.

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/k8s.io/ingress-nginx
Introduced in: 0Fixed in: 1.2.1
Fixgo get k8s.io/ingress-nginx@v1.2.1

References