Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-863x-868h-968x

Опубликовано: 24 мая 2023
Источник: github
Github: Прошло ревью
CVSS3: 6.5

Описание

Ingress-nginx path sanitization can be bypassed with newline character

A security issue was discovered in ingress-nginx where a user that can create or update ingress objects can use a newline character to bypass the sanitization of the spec.rules[].http.paths[].path field of an Ingress object (in the networking.k8s.io or extensions API group) to obtain the credentials of the ingress-nginx controller. In the default configuration, that credential has access to all secrets in the cluster.

Пакеты

Наименование

k8s.io/ingress-nginx

go
Затронутые версииВерсия исправления

< 1.2.1

1.2.1

EPSS

Процентиль: 12%
0.00041
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-20

Связанные уязвимости

CVSS3: 7.6
nvd
больше 2 лет назад

A security issue was discovered in ingress-nginx where a user that can create or update ingress objects can use a newline character to bypass the sanitization of the `spec.rules[].http.paths[].path` field of an Ingress object (in the `networking.k8s.io` or `extensions` API group) to obtain the credentials of the ingress-nginx controller. In the default configuration, that credential has access to all secrets in the cluster.

EPSS

Процентиль: 12%
0.00041
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-20