TGViewer
CatOps CatOps @catops · 5.07K subscribers
Post #2655 2.12K
We are continuing our security marathon with some news about very popular NGINX Ingress for Kubernetes.

Wiz Research discovered CVE-2025-1097, CVE-2025-1098, CVE-2025-24514 and CVE-2025-1974, a series of unauthenticated Remote Code Execution vulnerabilities in Ingress NGINX Controller for Kubernetes.

Exploiting these vulnerabilities can lead to unauthorized access to cluster secrets as well as remote code execution inside the ingress pod.

This vulnerability is fixed in Ingress NGINX Controller version 1.12.1 and 1.11.5, but if you cannot upgrade right now for whatever reason, Wiz has other recommendations on how to mitigate this.

P.S. Many thanks to the chat for sharing this story!

#security #kubernetes #nginx
wiz.io CVE-2025-1974: The IngressNightmare in Kubernetes | Wiz Blog Wiz Research uncovered RCE vulnerabilities (CVE-2025-1097, 1098, 24514, 1974) in Ingress NGINX for Kubernetes allowing cluster-wide secret access.
  • ❤ 8
  • 🔥 3
  • 👍 2
  • 😁 1
More from @catops
  1. Oct 1, 2026​​I traded my personal information for this report, so you don’t have to! DataDog presents…
  2. Sep 29, 2026A Cybersecurity books bundle by O’Reilly on Humble Bundle. The bundle is fresh and is stil…
  3. Sep 28, 2026​​For today’s Donations Monday, I’d like to remind you about a fundraiser for a pickup tru…
  4. Sep 26, 2026Here’s Datadog’s take on the increased load on CI. In this article they explain how their…
  5. Sep 25, 2026A new chapter of the CatOps Digest is here! https://newsletter.catops.dev/p/catops-digest-…
  6. Sep 24, 2026Shopify wrote an article on them moving from React Native to the native code for their mob…
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →