Don’t miss the news regarding five recent critical vulnerabilities in ingress-nginx, including CVE-2025-1974 scored at 9.8 CVSS!
The Kubernetes blog post states that over 40% of Kubernetes administrators rely on ingress-nginx and should take action immediately. Otherwise, a malicious user with no credentials can take over your Kubernetes cluster by exploiting configuration injection vulnerabilities via the Validating Admission Controller.
The latest ingress-nginx releases, v1.12.1 and v1.11.5, are already available with all five vulnerabilities fixed.
Find more details in this post from the Kubernetes Security Response Committee and this detailed article from Wiz.
#news #security
Post #181
1.26K
- 👍 4
- ❤ 1