CVE-2025-1974: Critical Unauthenticated RCE Vulnerability in Ingress NGINX for Kubernetes
ID: ce442f35-1a04-53f3-9778-9ebc6a975457
STIX ID: report--ce442f35-1a04-53f3-9778-9ebc6a975457
Feed Name: Arctic Wolf
Threat Score
On March 24, 2025, ingress-nginx maintainers released fixes for multiple vulnerabilities, including CVE-2025-1974 — a critical unauthenticated RCE via the ingress-nginx Validating Admission Controller that can allow actors on the Pod network to inject arbitrary NGINX configuration and potentially take over Kubernetes clusters; affected versions are prior to 1.12.1 and 1.11.5 and users are advised to upgrade or disable the Validating Admission Controller as a temporary mitigation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
