Описание
Kubernetes ingress exposes sensitive information
Versions < 1.5 of the Kubernetes ingress default backend, which handles invalid ingress traffic, exposed prometheus metrics publicly.
Пакеты
Наименование
k8s.io/ingress-nginx
go
Затронутые версииВерсия исправления
< 1.5
1.5
Связанные уязвимости
CVSS3: 5.3
redhat
около 6 лет назад
Versions < 1.5 of the Kubernetes ingress default backend, which handles invalid ingress traffic, exposed prometheus metrics publicly.
CVSS3: 5.3
nvd
около 6 лет назад
Versions < 1.5 of the Kubernetes ingress default backend, which handles invalid ingress traffic, exposed prometheus metrics publicly.