#VU102099 Input validation error in Ingress-NGINX Controller for Kubernetes - CVE-2024-7646
Published: December 30, 2024
Ingress-NGINX Controller for Kubernetes
Kubernetes
Description
The vulnerability allows a remote user to perform a denial of service (DoS) attack.
The vulnerability exists due to in the default configuration some credential has access to all secrets in the cluster.. A remote user with permission to create Ingress objects (in the `networking.k8s.io` or `extensions` API group) can bypass annotation validation to inject arbitrary commands and obtain the credentials of the ingress-nginx controller.