Permissions, Privileges, and Access Controls in Ingress-NGINX Controller for Kubernetes - CVE-2025-24514
Published: March 24, 2025 / Updated: June 13, 2025
Vulnerability identifier: #VU105988
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-24514
CWE-ID: CWE-264
Exploitation vector: Remote access
Exploit availability:
Public exploit is available
Vulnerability details
The vulnerability allows a remote user to escalate privileges on the system.
The vulnerability exists due to an error where the "auth-url" Ingress annotation can be used to inject configuration into nginx. A remote authenticated user can execute arbitrary code in the context of the ingress-nginx controller.
Affected software
Ingress-NGINX Controller for Kubernetes
SmartFabric Manager
Dell EMC Container Storage Modules
Red Hat OpenShift on IBM Cloud
SmartFabric Manager
Dell EMC Container Storage Modules
Red Hat OpenShift on IBM Cloud
How to mitigate CVE-2025-24514
Install update from vendor's website.
Ingress-NGINX Controller for Kubernetes - addressed in versions 1.11.5, 1.12.1
SmartFabric Manager - update to 1.3.0
Dell EMC Container Storage Modules - update to 1.14.0
Red Hat OpenShift on IBM Cloud - addressed in versions 4.16.60_1614, 4.17.52_1583, 4.18.38_1587, 4.19.29_1577, 4.20.19_1546
SmartFabric Manager - update to 1.3.0
Dell EMC Container Storage Modules - update to 1.14.0
Red Hat OpenShift on IBM Cloud - addressed in versions 4.16.60_1614, 4.17.52_1583, 4.18.38_1587, 4.19.29_1577, 4.20.19_1546