VDB
Sign up
HIGH8.8

GHSA-vg63-w3p9-jc9m

ingress-nginx controller - configuration injection via unsanitized mirror annotations

Quick fix

GHSA-vg63-w3p9-jc9m — k8s.io/ingress-nginx: upgrade to the fixed version with the command below.

go get k8s.io/ingress-nginx@v1.11.5

Details

A security issue was discovered in [ingress-nginx](https://github.com/kubernetes/ingress-nginx) where the `mirror-target` and `mirror-host` Ingress annotations can be used to inject arbitrary configuration into nginx. This can lead to arbitrary code execution in the context of the ingress-nginx controller, and disclosure of Secrets accessible to the controller. (Note that in the default installation, the controller can access all Secrets cluster-wide.)

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/k8s.io/ingress-nginx
Introduced in: 0Fixed in: 1.11.5
Fixgo get k8s.io/ingress-nginx@v1.11.5
Go/k8s.io/ingress-nginx
Introduced in: 1.12.0-beta.0Fixed in: 1.12.1
Fixgo get k8s.io/ingress-nginx@v1.12.1

References