Launch Week Day 1: Announcing Security Design Review
HIGH 7.6 Go

Ingress-nginx code injection via nginx.ingress.kubernetes.io/permanent-redirect annotation

GHSA-fp9f-44c2-cw27 · CVE-2023-5044 · GO-2024-2428

Published · Modified

Description

A security issue was identified in ingress-nginx where the nginx.ingress.kubernetes.io/permanent-redirect annotation on an Ingress object (in the networking.k8s.io or extensions API group) can be used to inject arbitrary commands, and obtain the credentials of the ingress-nginx controller. In the default configuration, that credential has access to all secrets in the cluster.

Ready to move

Start Securing

Free, no credit card | First findings in minutes