π₯ Critical vulnarabliiity in ingress-nginx controlller
9.8/10 π₯ https://github.com/advisories/GHSA-mgvx-rpfc-9mpv
If you're running Kubernetes with the ingress-nginx controller and are affected by the vulnerability described in GHSA-mgvx-rpfc-9mpv (CVE-2025-1974), you face several serious security risks:
Critical Security Risks
This vulnerability, published on March 25, 2025, is part of a set of critical flaws collectively named "IngressNightmare" with a CVSS score of 9.8[6]. The specific issues include:
- Unauthenticated Remote Code Execution (RCE): An attacker with access to the pod network can execute arbitrary code in the context of the ingress-nginx controller without authentication[1][2].
- Cluster-wide Secret Exposure: The vulnerability allows attackers to access and steal all secrets accessible to the controller. In default installations, the controller can access all secrets across all namespaces in the cluster[1][3].
- Complete Cluster Takeover: Due to the elevated privileges of the admission controller, successful exploitation could lead to full compromise of your Kubernetes environment[3][6].
- Public Exposure Risk: Over 6,500 clusters with publicly accessible admission controllers are at immediate risk, including those operated by Fortune 500 companies[8].
How the Vulnerability Works
The attack targets the admission controller component of the ingress-nginx controller:
1. The vulnerability allows attackers to inject arbitrary NGINX configuration remotely by sending a malicious ingress object directly to the admission controller[3].
2. When the controller processes this malicious object during validation, it causes the NGINX validator to execute malicious code[6][8].
3. The admission controller's elevated privileges and network accessibility create a critical escalation path, allowing an attacker to access sensitive resources across the entire cluster[3].
Required Action
To mitigate this issue, you should:
- Update immediately to one of the patched versions: 1.12.1, 1.11.5, or 1.10.7[6].
- Ensure your admission webhook endpoint is not exposed externally[6].
- Limit access to the admission controller to only the Kubernetes API Server[6].
- Temporarily disable the admission controller component if it's not needed[6].
This vulnerability affects approximately 43% of cloud environments, making it a widespread and serious threat to Kubernetes deployments[6].
Post #2037
2.17K