kubernetes-ingress-nginx
cpe:2.3:a:kubernetes:ingress-nginx:*:*:*:*:*:*:*
- v1.12.5
- v1.13.1
A vulnerability in ingress-nginx allows the `nginx.ingress.kubernetes.io/auth-proxy-set-headers` Ingress annotation to inject configuration into nginx. This injection can result in arbitrary code execution within the ingress-nginx controller and the unauthorized disclosure of Secrets accessible to the controller. By default, the controller has access to all Secrets across the cluster.
Exploitation of this vulnerability could lead to arbitrary code execution in the context of the ingress-nginx controller and the disclosure of cluster-wide Secrets accessible to the controller.
Users are advised to upgrade ingress-nginx to version 1.12.5, 1.13.1, or any later version. For upgrade instructions, refer to the official documentation on upgrading ingress-nginx.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.