#VU105990 Permissions, Privileges, and Access Controls in Ingress-NGINX Controller for Kubernetes - CVE-2025-1097
Published: March 24, 2025 / Updated: March 25, 2025
Ingress-NGINX Controller for Kubernetes
Kubernetes
Description
The vulnerability allows a remote user to escalate privileges on the system.
The vulnerability exists due to an error where the "auth-tls-match-cn" Ingress annotation can be used to inject configuration into nginx. A remote authenticated user can execute arbitrary code in the context of the ingress-nginx controller.