Permissions, Privileges, and Access Controls in Ingress-NGINX Controller for Kubernetes - CVE-2025-1098
Published: March 24, 2025 / Updated: March 25, 2025
Vulnerability details
The vulnerability allows a remote user to compromise the affected system.
The vulnerability exists due to "mirror-target" and "mirror-host" Ingress annotations can be used to inject arbitrary configuration into nginx. A remote user can execute arbitrary code in the context of the ingress-nginx controller and disclose Secrets accessible to the controller.
Affected software
SmartFabric Manager
Dell EMC Container Storage Modules
How to mitigate CVE-2025-1098
SmartFabric Manager - update to 1.3.0
Dell EMC Container Storage Modules - update to 1.14.0