CVE-2023-5044

HIGH7.6EPSS 10.6%

Ingress-nginx code injection via nginx.ingress.kubernetes.io/permanent-redirect annotation

發布日:2023/10/25修改日:2026/5/20
也稱為:GHSA-fp9f-44c2-cw27CGA-854f-8326-49p2GO-2024-2428

描述

A security issue was identified in [ingress-nginx](https://github.com/kubernetes/ingress-nginx) where the nginx.ingress.kubernetes.io/permanent-redirect annotation on an Ingress object (in the networking.k8s.io or extensions API group) can be used to inject arbitrary commands, and obtain the credentials of the ingress-nginx controller. In the default configuration, that credential has access to all secrets in the cluster.

受影響套件(2)

CVSS 分數

來源版本嚴重程度向量
osvCVSS 4.0CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N
osvCVSS 3.1HIGH7.6CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L

參考連結(7)