kubernetes/ingress-nginx
cpe:2.3:a:kubernetes:ingress-nginx:*:*:*:*:*:*:*
- < v1.11.0
- v1.11.0 - 1.11.4
- v1.12.0
A directory traversal vulnerability has been identified in the ingress-nginx Admission Controller feature. This issue arises because attacker-provided data is incorporated into filenames, leading to unauthorized access within the container's file system. The vulnerability could cause a denial-of-service condition or, when combined with other vulnerabilities, allow limited disclosure of Secret objects from the Kubernetes cluster.
Exploitation of this vulnerability could lead to unauthorized directory traversal within the container, causing a denial-of-service condition or, in conjunction with other vulnerabilities, allowing limited access to Secret objects from the Kubernetes cluster.
Users are advised to upgrade ingress-nginx to version 1.11.5, 1.12.1, or any later version. If an immediate upgrade is not possible, the Validating Admission Controller functionality can be disabled as a temporary measure.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.