Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 4

Количество 4

nvd логотип

CVE-2024-7646

почти 2 года назад

A security issue was discovered in ingress-nginx where an actor with permission to create Ingress objects (in the `networking.k8s.io` or `extensions` API group) can bypass annotation validation to inject arbitrary commands and obtain the credentials of the ingress-nginx controller. In the default configuration, that credential has access to all secrets in the cluster.

CVSS3: 8.8
EPSS: Средний
github логотип

GHSA-qx8j-xj5q-v7r3

почти 2 года назад

A security issue was discovered in ingress-nginx where an actor with permission to create Ingress objects (in the `networking.k8s.io` or `extensions` API group) can bypass annotation validation to inject arbitrary commands and obtain the credentials of the ingress-nginx controller. In the default configuration, that credential has access to all secrets in the cluster.

CVSS3: 8.8
EPSS: Средний
fstec логотип

BDU:2024-06271

почти 2 года назад

Уязвимость контроллера входящего трафика в кластере Kubernetes ingress-nginx, связанная с ошибками при обработке аннотаций Ingress-объектов, позволяющая нарушителю повысить свои привилегии

CVSS3: 8.8
EPSS: Средний
redos логотип

ROS-20250814-02

12 месяцев назад

Уязвимость golang-k8s-ingress-nginx

CVSS3: 8.8
EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2024-7646

A security issue was discovered in ingress-nginx where an actor with permission to create Ingress objects (in the `networking.k8s.io` or `extensions` API group) can bypass annotation validation to inject arbitrary commands and obtain the credentials of the ingress-nginx controller. In the default configuration, that credential has access to all secrets in the cluster.

CVSS3: 8.8
27%
Средний
почти 2 года назад
github логотип
GHSA-qx8j-xj5q-v7r3

A security issue was discovered in ingress-nginx where an actor with permission to create Ingress objects (in the `networking.k8s.io` or `extensions` API group) can bypass annotation validation to inject arbitrary commands and obtain the credentials of the ingress-nginx controller. In the default configuration, that credential has access to all secrets in the cluster.

CVSS3: 8.8
27%
Средний
почти 2 года назад
fstec логотип
BDU:2024-06271

Уязвимость контроллера входящего трафика в кластере Kubernetes ingress-nginx, связанная с ошибками при обработке аннотаций Ingress-объектов, позволяющая нарушителю повысить свои привилегии

CVSS3: 8.8
27%
Средний
почти 2 года назад
redos логотип
ROS-20250814-02

Уязвимость golang-k8s-ingress-nginx

CVSS3: 8.8
27%
Средний
12 месяцев назад

Уязвимостей на страницу