PT-2024-5586 · Unknown+1 · Ingress-Nginx+1
André Storfjord Kristiansen
+1
·
Published
2024-08-16
·
Updated
2025-09-04
·
CVE-2024-7646
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
ingress-nginx versions prior to 1.12
Description
A security issue was discovered in ingress-nginx where an actor with permission to create Ingress objects can bypass annotation validation to inject arbitrary commands and obtain the credentials of the ingress-nginx controller. In the default configuration, that credential has access to all secrets in the cluster. The vulnerability allows an attacker to inject malicious content into certain annotations, bypassing the intended validation checks, which can lead to arbitrary command injection and potential access to the cluster's secrets.
Recommendations
For versions prior to 1.12, update to version 1.12 or later to resolve the issue.
As a temporary workaround, consider restricting the use of certain annotations in Ingress resources to minimize the risk of exploitation.
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Red Os
Ingress-Nginx