Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-25742

Опубликовано: 21 окт. 2021
Источник: redhat
CVSS3: 7.6
EPSS Низкий

Описание

A security issue was discovered in ingress-nginx where a user that can create or update ingress objects can use the custom snippets feature to obtain all secrets in the cluster.

Отчет

OpenShift Container Platform does not use NGINX for Ingress and is therefore not affected by this vulnerability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/management-ingress-rhel8Not affected
Red Hat OpenShift Container Platform 3.11atomic-openshiftNot affected
Red Hat OpenShift Container Platform 4openshiftNot affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-522
https://bugzilla.redhat.com/show_bug.cgi?id=2012036k8s.io/ingress-nginx: Custom snippets allows retrieval of ingress-nginx serviceaccount token and secrets across all namespaces

EPSS

Процентиль: 67%
0.0054
Низкий

7.6 High

CVSS3

Связанные уязвимости

CVSS3: 7.6
nvd
больше 4 лет назад

A security issue was discovered in ingress-nginx where a user that can create or update ingress objects can use the custom snippets feature to obtain all secrets in the cluster.

github
больше 3 лет назад

A security issue was discovered in ingress-nginx where a user that can create or update ingress objects can use the custom snippets feature to obtain all secrets in the cluster.

EPSS

Процентиль: 67%
0.0054
Низкий

7.6 High

CVSS3