CVE-2023-5044

HIGH7.6EPSS 10.6%

Ingress-nginx code injection via nginx.ingress.kubernetes.io/permanent-redirect annotation

Published: 10/25/2023Modified: 5/20/2026
Also known as:GHSA-fp9f-44c2-cw27CGA-854f-8326-49p2GO-2024-2428

Description

A security issue was identified in [ingress-nginx](https://github.com/kubernetes/ingress-nginx) where the nginx.ingress.kubernetes.io/permanent-redirect annotation on an Ingress object (in the networking.k8s.io or extensions API group) can be used to inject arbitrary commands, and obtain the credentials of the ingress-nginx controller. In the default configuration, that credential has access to all secrets in the cluster.

Affected packages (2)

CVSS scores

SourceVersionSeverityVector
osvCVSS 4.0CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N
osvCVSS 3.1HIGH7.6CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L

References (7)