A security issue was discovered in ingress-nginx https://github.com/kubernetes/ingress-nginx where attacker-provided data are included in a filename by the ingress-nginx Admission Controller feature, resulting in directory traversal within the container. This could result in denial of service, or when combined with other vulnerabilities, limited disclosure of Secret objects from the cluster.
Metrics
Affected Vendors & Products
References
History
Wed, 26 Mar 2025 02:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
References |
|
Tue, 25 Mar 2025 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Mon, 24 Mar 2025 23:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A security issue was discovered in ingress-nginx https://github.com/kubernetes/ingress-nginx where attacker-provided data are included in a filename by the ingress-nginx Admission Controller feature, resulting in directory traversal within the container. This could result in denial of service, or when combined with other vulnerabilities, limited disclosure of Secret objects from the cluster. | |
Title | ingress-nginx controller - auth secret file path traversal vulnerability | |
Weaknesses | CWE-20 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: kubernetes
Published: 2025-03-24T23:29:25.215Z
Updated: 2025-03-25T13:39:50.057Z
Reserved: 2025-01-23T00:50:17.928Z
Link: CVE-2025-24513

Updated: 2025-03-25T13:39:25.280Z

Status : Received
Published: 2025-03-25T00:15:14.900
Modified: 2025-03-25T00:15:14.900
Link: CVE-2025-24513
