Permissions, Privileges, and Access Controls in Ingress-NGINX Controller for Kubernetes - CVE-2025-1097
Published: March 24, 2025 / Updated: March 25, 2025
Vulnerability details
The vulnerability allows a remote user to escalate privileges on the system.
The vulnerability exists due to an error where the "auth-tls-match-cn" Ingress annotation can be used to inject configuration into nginx. A remote authenticated user can execute arbitrary code in the context of the ingress-nginx controller.
Affected software
SmartFabric Manager
Dell EMC Container Storage Modules
How to mitigate CVE-2025-1097
SmartFabric Manager - update to 1.3.0
Dell EMC Container Storage Modules - update to 1.14.0