VDB
Sign up
HIGH8.8

GHSA-823x-fv5p-h7hw

ngress-nginx controller - configuration injection via unsanitized auth-tls-match-cn annotation

Quick fix

GHSA-823x-fv5p-h7hw — k8s.io/ingress-nginx: upgrade to the fixed version with the command below.

go get k8s.io/ingress-nginx@v1.11.5

Details

A security issue was discovered in [ingress-nginx](https://github.com/kubernetes/ingress-nginx) where the `auth-tls-match-cn` Ingress annotation can be used to inject configuration into nginx. This can lead to arbitrary code execution in the context of the ingress-nginx controller, and disclosure of Secrets accessible to the controller. (Note that in the default installation, the controller can access all Secrets cluster-wide.)

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/k8s.io/ingress-nginx
Introduced in: 0Fixed in: 1.11.5
Fixgo get k8s.io/ingress-nginx@v1.11.5
Go/k8s.io/ingress-nginx
Introduced in: 1.12.0-beta.0Fixed in: 1.12.1
Fixgo get k8s.io/ingress-nginx@v1.12.1

References