Close Menu
    DevStackTipsDevStackTips
    • Home
    • News & Updates
      1. Tech & Work
      2. View All

      Sunshine And March Vibes (2025 Wallpapers Edition)

      May 16, 2025

      The Case For Minimal WordPress Setups: A Contrarian View On Theme Frameworks

      May 16, 2025

      How To Fix Largest Contentful Paint Issues With Subpart Analysis

      May 16, 2025

      How To Prevent WordPress SQL Injection Attacks

      May 16, 2025

      Microsoft has closed its “Experience Center” store in Sydney, Australia — as it ramps up a continued digital growth campaign

      May 16, 2025

      Bing Search APIs to be “decommissioned completely” as Microsoft urges developers to use its Azure agentic AI alternative

      May 16, 2025

      Microsoft might kill the Surface Laptop Studio as production is quietly halted

      May 16, 2025

      Minecraft licensing robbed us of this controversial NFL schedule release video

      May 16, 2025
    • Development
      1. Algorithms & Data Structures
      2. Artificial Intelligence
      3. Back-End Development
      4. Databases
      5. Front-End Development
      6. Libraries & Frameworks
      7. Machine Learning
      8. Security
      9. Software Engineering
      10. Tools & IDEs
      11. Web Design
      12. Web Development
      13. Web Security
      14. Programming Languages
        • PHP
        • JavaScript
      Featured

      The power of generators

      May 16, 2025
      Recent

      The power of generators

      May 16, 2025

      Simplify Factory Associations with Laravel’s UseFactory Attribute

      May 16, 2025

      This Week in Laravel: React Native, PhpStorm Junie, and more

      May 16, 2025
    • Operating Systems
      1. Windows
      2. Linux
      3. macOS
      Featured

      Microsoft has closed its “Experience Center” store in Sydney, Australia — as it ramps up a continued digital growth campaign

      May 16, 2025
      Recent

      Microsoft has closed its “Experience Center” store in Sydney, Australia — as it ramps up a continued digital growth campaign

      May 16, 2025

      Bing Search APIs to be “decommissioned completely” as Microsoft urges developers to use its Azure agentic AI alternative

      May 16, 2025

      Microsoft might kill the Surface Laptop Studio as production is quietly halted

      May 16, 2025
    • Learning Resources
      • Books
      • Cheatsheets
      • Tutorials & Guides
    Home»Development»Multiple CVEs Found in Ingress-NGINX—Patch Now to Prevent Cluster Compromise

    Multiple CVEs Found in Ingress-NGINX—Patch Now to Prevent Cluster Compromise

    March 27, 2025

    Ingress-NGINX Controller

    A set of vulnerabilities have been identified in Ingress-NGINX Controller for Kubernetes, posing a risk to organizations relying on the affected versions. These vulnerabilities impact versions prior to NGINX Controller 1.12.1 and 1.11.5, and could allow unauthorized remote code execution and potential full cluster takeover.

    Technical users leveraging Kubernetes for containerized workloads should immediately patch their systems to the latest version to mitigate these risks.

    Ingress-NGINX Controller Background: What Has Happened?

    The Australian Cyber Security Centre has released an advisory detailing multiple vulnerabilities affecting Ingress-NGINX Controller. The flaws stem from improper handling of ingress annotations and attacker-provided data, leading to arbitrary code execution and secret disclosures.

    Below are the key vulnerabilities identified:

    1. CVE-2025-1097: Auth-TLS-Match-CN Ingress Annotation Vulnerability

    A security issue exists where the auth-tls-match-cn Ingress annotation can be exploited to inject unauthorized configurations into NGINX.

    • Impact: Enables arbitrary code execution in the context of the Ingress-NGINX controller.
    • Risk: Unauthorized access to all Secrets across namespaces, compromising the cluster’s security.
    2. CVE-2025-1098: Mirror-Target and Mirror-Host Annotations Vulnerability

    The mirror-target and mirror-host Ingress annotations can be misused to insert arbitrary configurations into NGINX.

    • Impact: Remote execution of malicious code within the Ingress-NGINX controller.
    • Risk: Exposes sensitive cluster-wide Secrets, leading to potential system compromise.
    3. CVE-2025-1974: Unauthenticated Access to Pod Network

    Under certain conditions, an unauthenticated attacker with access to the pod network can achieve arbitrary code execution.

    • Impact: Compromised controller integrity.
    • Risk: Attackers can extract Secrets from the cluster and potentially gain full control.
    4. CVE-2025-24513: Directory Traversal via Ingress-NGINX Admission Controller

    A vulnerability in the Ingress-NGINX Admission Controller allows attacker-provided data to be included in filenames, leading to directory traversal within the container.

    • Impact: Can result in Denial of Service (DoS).
    • Risk: In some cases, can expose Secret objects within the cluster.
    5. CVE-2025-24514: Auth-URL Ingress Annotation Exploit

    The auth-url Ingress annotation can be used to inject malicious configurations into NGINX.

    • Impact: Allows attackers to remotely execute code within the controller.
    • Risk: Grants unauthorized access to Secrets across namespaces.

    Why This Matters

    Ingress-NGINX Controller plays a critical role in routing external traffic to services within a Kubernetes cluster. Exploiting these vulnerabilities can lead to:

    • Remote Code Execution (RCE): Attackers can execute arbitrary commands on the Ingress controller.
    • Cluster-Wide Secrets Exposure: Sensitive credentials, API keys, and other secrets can be compromised.
    • Complete Cluster Takeover: Unauthorized access could lead to a total compromise of Kubernetes infrastructure.

    Mitigation: How to Stay Secure

    To protect against these vulnerabilities, the Australian Signals Directorate’s (ASD) Australian Cyber Security Centre (ACSC) recommends the following measures:

    1. Upgrade to the Latest Version
      • Immediately update Ingress-NGINX Controller to version 1.12.1 or 1.11.5 to patch these security issues.
    2. Review Kubernetes Security Guidance
      • Regularly monitor updates from the official Ingress-NGINX GitHub Repository to stay informed about security patches and advisories.
    3. Disable External Access to the Admission Webhook Endpoint
      • Ensure the admission webhook endpoint is not publicly accessible to prevent external attackers from exploiting it.
    4. Addressing CVE-2025-1974
      • Due to the severity of this vulnerability, validation of the generated NGINX configuration has been disabled during Ingress resource validation.
      • While the system still performs checks before actual loading, invalid Ingress resources may prevent NGINX from updating its configuration.
      • Recommended Actions:
        • Enable annotation validation.
        • Disable snippet annotations to minimize risks.
        • Monitor Ingress-NGINX logs for errors, particularly lines preceded by Error.

    The Ingress-NGINX vulnerabilities present a serious risk to Kubernetes clusters, with potential consequences including unauthorized remote execution, credential leaks, and cluster-wide compromise. Organizations using affected versions should immediately upgrade to secure their environments.

    By staying informed and following best practices, technical teams can minimize the attack surface and prevent exploitation of these critical flaws.

    Source: Read More

    Facebook Twitter Reddit Email Copy Link
    Previous ArticleTop 3 MS Office Exploits Hackers Use in 2025 – Stay Alert!
    Next Article SnapCenter Security Flaw Rated Critical—NetApp Urges Immediate Patch

    Related Posts

    Security

    Nmap 7.96 Launches with Lightning-Fast DNS and 612 Scripts

    May 17, 2025
    Common Vulnerabilities and Exposures (CVEs)

    CVE-2024-47893 – VMware GPU Firmware Memory Disclosure

    May 17, 2025
    Leave A Reply Cancel Reply

    Continue Reading

    Your Microsoft Office apps will soon launch faster – but the Speed Boost is optional

    News & Updates

    Over a decade of unreleased classic Halo content just leaked amid major “Digsite” controversy

    Development

    Can LLMs Visualize Graphics? Assessing Symbolic Program Understanding in AI

    Development

    AirTag too quiet? This alternative is much louder and works with Android and iPhone

    News & Updates

    Highlights

    The rise of “soft” skills: How GenAI is reshaping developer roles

    December 20, 2024

    The software development landscape is undergoing a profound transformation as generative AI (GenAI) reshapes traditional…

    Microsoft just confirmed the dates for Build 2025 — expect a heavy dose of AI

    February 5, 2025

    Recreation of the GitHub mobile app header but for web using Trig.js

    March 18, 2025

    Data Loading with Python and AI

    April 17, 2025
    © DevStackTips 2025. All rights reserved.
    • Contact
    • Privacy Policy

    Type above and press Enter to search. Press Esc to cancel.