Ingress Nightmare: Critical Unauthenticated Remote Code Execution Vulnerabilities in Ingress-NGINX
ID: bce22da8-82ea-5d4e-be60-c8cc564072f3
STIX ID: report--bce22da8-82ea-5d4e-be60-c8cc564072f3
Feed Name: SOCRadar Blog
Threat Score
On March 24, 2025 a security advisory disclosed five vulnerabilities in ingress-nginx — most critically CVE-2025-1974 (CVSS 9.8) — that enable unauthenticated configuration injection, remote code execution, and potential exposure of Kubernetes Secrets across affected versions (all prior to v1.11.0, v1.11.0–v1.11.4, and v1.12.0); administrators are urged to upgrade to v1.12.1 or v1.11.5 immediately or apply temporary mitigations such as disabling the Validating Admission Controller.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
