Public-facing Kubernetes clusters at risk of takeover thanks to Ingress-Nginx flaw
ID: 0982bfe4-740b-591c-a595-164dbc8d48dc
STIX ID: report--0982bfe4-740b-591c-a595-164dbc8d48dc
Feed Name: The Register (Security)
Threat Score
Wiz disclosed critical vulnerabilities in the Ingress‑Nginx admission controller — including CVE‑2025‑1974 (CVSS 9.8) — that permit injection of malicious Nginx configuration leading to remote code execution and potential full Kubernetes cluster takeover; fixes (Ingress‑Nginx Controller 1.12.1 / 1.11.5) and mitigations (restrict admission controller network access or disable it) have been released.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
