SB20241230123 - Input validation error in kubernetes ingress-nginx
Published: December 30, 2024
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Input validation error (CVE-ID: CVE-2024-7646)
The vulnerability allows a remote user to perform a denial of service (DoS) attack.
The vulnerability exists due to in the default configuration some credential has access to all secrets in the cluster.. A remote user with permission to create Ingress objects (in the `networking.k8s.io` or `extensions` API group) can bypass annotation validation to inject arbitrary commands and obtain the credentials of the ingress-nginx controller.
Remediation
Install update from vendor's website.