#VU105986 Permissions, Privileges, and Access Controls in Ingress-NGINX Controller for Kubernetes - CVE-2025-1098
Published: March 24, 2025 / Updated: March 25, 2025
Ingress-NGINX Controller for Kubernetes
Kubernetes
Description
The vulnerability allows a remote user to compromise the affected system.
The vulnerability exists due to "mirror-target" and "mirror-host" Ingress annotations can be used to inject arbitrary configuration into nginx. A remote user can execute arbitrary code in the context of the ingress-nginx controller and disclose Secrets accessible to the controller.