VDB
Sign up
HIGH7.6

GHSA-fp9f-44c2-cw27

Ingress-nginx code injection via nginx.ingress.kubernetes.io/permanent-redirect annotation

Quick fix

GHSA-fp9f-44c2-cw27 — k8s.io/ingress-nginx: upgrade to the fixed version with the command below.

go get k8s.io/ingress-nginx@v1.9.0

Details

A security issue was identified in [ingress-nginx](https://github.com/kubernetes/ingress-nginx) where the nginx.ingress.kubernetes.io/permanent-redirect annotation on an Ingress object (in the networking.k8s.io or extensions API group) can be used to inject arbitrary commands, and obtain the credentials of the ingress-nginx controller. In the default configuration, that credential has access to all secrets in the cluster.

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/k8s.io/ingress-nginx
Introduced in: 0Fixed in: 1.9.0
Fixgo get k8s.io/ingress-nginx@v1.9.0

References