Critical Unauthenticated Remote Code Execution Vulnerabilities inIngress NGINX
ID: 6f8f821f-e7af-5370-a02d-2c6936f99a5c
STIX ID: report--6f8f821f-e7af-5370-a02d-2c6936f99a5c
Feed Name: Kudelski Security
Wiz Research disclosed multiple critical unauthenticated RCE vulnerabilities in the Ingress NGINX Controller ("IngressNightmare") that permit arbitrary command execution via unsanitized ingress annotations and the admission controller, potentially exposing cluster-wide secrets and enabling full Kubernetes cluster compromise; immediate mitigation recommended includes upgrading affected controllers (prior to 1.12.1 and 1.11.5), restricting admission webhook access, and increased monitoring.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
