Skip to content
New issue

Have a question about this project? # for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “#”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? # to your account

x/vulndb: potential Go vuln in k8s.io/ingress-nginx: GHSA-vg63-w3p9-jc9m #3568

Closed
GoVulnBot opened this issue Mar 25, 2025 · 1 comment
Closed
Labels

Comments

@GoVulnBot
Copy link

Advisory GHSA-vg63-w3p9-jc9m references a vulnerability in the following Go modules:

Module
k8s.io/ingress-nginx

Description:
A security issue was discovered in ingress-nginx where the mirror-target and mirror-host Ingress annotations can be used to inject arbitrary configuration into nginx. This can lead to arbitrary code execution in the context of the ingress-nginx controller, and disclosure of Secrets accessible to the controller. (Note that in the default installation, the controller can access all Secrets cluster-wide.)

References:

Cross references:

See doc/quickstart.md for instructions on how to triage this report.

id: GO-ID-PENDING
modules:
    - module: k8s.io/ingress-nginx
      non_go_versions:
        - fixed: 1.11.5
        - introduced: 1.12.0-beta.0
        - fixed: 1.12.1
      vulnerable_at: 0.0.0-20250325144035-1d7abc12ef72
summary: |-
    ingress-nginx controller - configuration injection via unsanitized mirror
    annotations in k8s.io/ingress-nginx
cves:
    - CVE-2025-1098
ghsas:
    - GHSA-vg63-w3p9-jc9m
references:
    - advisory: https://github.com/advisories/GHSA-vg63-w3p9-jc9m
    - advisory: https://nvd.nist.gov/vuln/detail/CVE-2025-1098
    - report: https://github.com/kubernetes/kubernetes/issues/131008
    - web: https://github.com/kubernetes/ingress-nginx/releases/tag/controller-v1.11.5
    - web: https://github.com/kubernetes/ingress-nginx/releases/tag/controller-v1.12.1
    - web: https://groups.google.com/g/kubernetes-security-announce/c/2qa9DFtN0cQ
source:
    id: GHSA-vg63-w3p9-jc9m
    created: 2025-03-25T16:01:37.051050511Z
review_status: UNREVIEWED

@gopherbot
Copy link
Contributor

Change https://go.dev/cl/660559 mentions this issue: data/reports: add 28 reports

# for free to join this conversation on GitHub. Already have an account? # to comment
Labels
Projects
None yet
Development

No branches or pull requests

3 participants