Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Ingress-nginx custom snippets allows retrieval of ingress-nginx serviceaccount token and secrets across all namespaces
Vulnerability Description
A security issue was discovered in ingress-nginx where a user that can create or update ingress objects can use the custom snippets feature to obtain all secrets in the cluster.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L
Vulnerability Type
输入验证不恰当
Vulnerability Title
ingress-nginx 安全漏洞
Vulnerability Description
ingress-nginx是开源的Kubernetes 的入口控制器,使用NGINX作为反向代理和负载均衡器。 ingress-nginx 存在安全漏洞,该漏洞源于创建或更新 ingress 对象的用户可以使用自定义片段功能来获取集群中的所有机密。
CVSS Information
N/A
Vulnerability Type
N/A