Urgent: New Security Flaws Discovered in NGINX Ingress Controller for Kubernetes

Discussion in 'News Aggregator' started by The Hacker News, 30 Oct 2023.

  1. Three unpatched high-severity security flaws have been disclosed in the NGINX Ingress controller for Kubernetes that could be weaponized by a threat actor to steal secret credentials from the cluster. The vulnerabilities are as follows - CVE-2022-4886 (CVSS score: 8.8) - Ingress-nginx path sanitization can be bypassed to obtain the credentials of the ingress-nginx controller CVE-2023-5043 (

    Continue reading...
     

Share This Page

Loading...