VDB

GCVE-110-NCSC-2025-95

GCVE-110-NCSC-2025-95
Advisory PublishedCVSS 9.8/10
Vulnetix · Advisory published March 25, 2025
Kubernetes heeft een aantal kwetsbaarheden in de Ingress NGINX Controller verholpen. Deze kwetsbaarheden stellen kwaadwillenden in staat een ongeauthenticeerde remote code execution (RCE) uit voeren.

Weaknesses (CWE)

CWE-653Improper Isolation or CompartmentalizationCWE-20Improper Input Validation

Risk Scores

CVSS 3.1
9.8/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
Kubernetesvers:semver/<=1.11.4
Kubernetesvers:unknown/1.12.0

References

advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›