HIGH7.6
GHSA-fp9f-44c2-cw27
Ingress-nginx code injection via nginx.ingress.kubernetes.io/permanent-redirect annotation
Quick fix
GHSA-fp9f-44c2-cw27 — k8s.io/ingress-nginx: upgrade to the fixed version with the command below.
go get k8s.io/ingress-nginx@v1.9.0Details
A security issue was identified in [ingress-nginx](https://github.com/kubernetes/ingress-nginx) where the nginx.ingress.kubernetes.io/permanent-redirect annotation on an Ingress object (in the networking.k8s.io or extensions API group) can be used to inject arbitrary commands, and obtain the credentials of the ingress-nginx controller. In the default configuration, that credential has access to all secrets in the cluster.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2023-5044[ADVISORY]
- https://github.com/kubernetes/ingress-nginx/issues/10572[WEB]
- https://github.com/kubernetes/ingress-nginx[PACKAGE]
- https://groups.google.com/g/kubernetes-security-announce/c/ukuYYvRNel0[WEB]
- https://security.netapp.com/advisory/ntap-20240307-0012[WEB]
- http://www.openwall.com/lists/oss-security/2023/10/25/3[WEB]