PT-2022-3992 · Nginx · Nginx Ingress Controller
Published
2022-08-04
·
Updated
2023-11-06
·
CVE-2022-30535
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:L/Au:S/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
NGINX Ingress Controller versions 1.x and earlier
NGINX Ingress Controller versions 2.x before 2.3.0
Description
The issue is related to insufficient input validation, allowing an authorized attacker to obtain secrets available to the NGINX Ingress Controller by creating or updating ingress objects. This can lead to the disclosure of protected information.
Recommendations
For versions 1.x, consider disabling the creation or update of ingress objects until a patch is available.
For versions 2.x before 2.3.0, update to version 2.3.0 or later to resolve the issue.
As a temporary workaround, restrict access to the NGINX Ingress Controller to minimize the risk of exploitation.
Fix
Information Disclosure
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Nginx Ingress Controller