PT-2020-8511 · Kubernetes · Kubernetes Ingress Default Backend
Nicoleg25
·
Published
2020-01-14
·
Updated
2022-05-24
·
CVE-2018-1002104
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
Kubernetes ingress default backend versions prior to 1.5
Description:
The issue concerns the exposure of Prometheus metrics publicly due to the Kubernetes ingress default backend handling invalid ingress traffic improperly.
Recommendations:
For versions prior to 1.5, update to version 1.5 or later to resolve the issue.
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Kubernetes Ingress Default Backend