PT-2025-13007 · Unknown+1 · Ingress-Nginx+2

CVE-2025-2787

·

Publicado

2025-03-26

·

Atualizado

2025-04-01

CVSS v3.1

8.8

Alta

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions KNIME Business Hub versions prior to 1.10.4 KNIME Business Hub versions prior to 1.11.4 KNIME Business Hub versions prior to 1.12.4 KNIME Business Hub versions prior to 1.13.3
Description The issue affects the ingress-nginx component, potentially allowing a complete takeover of the Kubernetes cluster in the worst case. However, since the affected component is only reachable from within the cluster and requires an authenticated user, the severity is slightly lower.
Recommendations For versions prior to 1.10.4, update to version 1.10.4 or above. For versions prior to 1.11.4, update to version 1.11.4 or above. For versions prior to 1.12.4, update to version 1.12.4 or above. For versions prior to 1.13.3, update to version 1.13.3 or above.

Correção

Code Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2025-2787

Produtos afetados

Knime Business Hub
Kubernetes
Ingress-Nginx