VDB
CVE-2024-7646
CVE-2024-7646
PUBLISHED
A security issue was discovered in ingress-nginx where an actor with permission to create Ingress objects (in the `networking.k8s.io` or `extensions` API group) can bypass annotation validation to inject arbitrary commands and obtain the credentials of the ingress-nginx controller. In the default configuration, that credential has access to all secrets in the cluster.
EPSS 22.18% · 95.9th percentile
Risk Scores
EPSS Score
22.18%
95.9th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Bitnami | nginx-ingress-controller | 0 |
| Bitnami | nginx-ingress-controller | 0 |
Timeline
- Aug 16, 2024 CVE Published
- Aug 17, 2024 EPSS Score
- Aug 19, 2024 CVE Updated
- Oct 5, 2024 Coalition ESS Score
- Oct 22, 2024 PoC Published
- Mar 4, 2025 Coalition ESS Score
- Mar 17, 2025 EPSS Score
- Mar 22, 2025 EPSS Score
- Mar 23, 2025 EPSS Score
- Mar 26, 2025 PoC Published
- Mar 28, 2025 EPSS Score
- Mar 28, 2025 PoC Published
References
- https://github.com/kubernetes/ingress-nginx/pull/11719 url
- https://github.com/kubernetes/ingress-nginx/pull/11721 url
- https://github.com/kubernetes/kubernetes/issues/126744 url
- https://groups.google.com/g/kubernetes-security-announce/c/a1__cKjWkfA url
- http://www.openwall.com/lists/oss-security/2024/08/16/5 url
- https://nvd.nist.gov/vuln/detail/CVE-2024-7646 url