A security issue was discovered in ingress-nginx https://github.com/kubernetes/ingress-nginx where attacker-provided data are included in a filename by the ingress-nginx Admission Controller feature, resulting in directory traversal within the container. This could result in denial of service, or when combined with other vulnerabilities, limited disclosure of Secret objects from the cluster.
History

Wed, 26 Mar 2025 02:15:00 +0000


Tue, 25 Mar 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 24 Mar 2025 23:45:00 +0000

Type Values Removed Values Added
Description A security issue was discovered in ingress-nginx https://github.com/kubernetes/ingress-nginx where attacker-provided data are included in a filename by the ingress-nginx Admission Controller feature, resulting in directory traversal within the container. This could result in denial of service, or when combined with other vulnerabilities, limited disclosure of Secret objects from the cluster.
Title ingress-nginx controller - auth secret file path traversal vulnerability
Weaknesses CWE-20
References
Metrics cvssV3_1

{'score': 4.8, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: kubernetes

Published: 2025-03-24T23:29:25.215Z

Updated: 2025-03-25T13:39:50.057Z

Reserved: 2025-01-23T00:50:17.928Z

Link: CVE-2025-24513

cve-icon Vulnrichment

Updated: 2025-03-25T13:39:25.280Z

cve-icon NVD

Status : Received

Published: 2025-03-25T00:15:14.900

Modified: 2025-03-25T00:15:14.900

Link: CVE-2025-24513

cve-icon Redhat

Severity :

Publid Date: 2025-03-24T23:29:25Z

Links: CVE-2025-24513 - Bugzilla