VDB
Sign up
CRITICAL9.8

GHSA-mgvx-rpfc-9mpv

ingress-nginx admission controller RCE escalation

Quick fix

GHSA-mgvx-rpfc-9mpv — k8s.io/ingress-nginx: upgrade to the fixed version with the command below.

go get k8s.io/ingress-nginx@v1.11.5

Details

A security issue was discovered in Kubernetes where under certain conditions, an unauthenticated attacker with access to the pod network can achieve arbitrary code execution in the context of the ingress-nginx controller. This can lead to disclosure of Secrets accessible to the controller. (Note that in the default installation, the controller can access all Secrets cluster-wide.)

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/k8s.io/ingress-nginx
Introduced in: 0Fixed in: 1.11.5
Fixgo get k8s.io/ingress-nginx@v1.11.5
Go/k8s.io/ingress-nginx
Introduced in: 1.12.0-beta.0Fixed in: 1.12.1
Fixgo get k8s.io/ingress-nginx@v1.12.1

References