Known Vulnerabilities for Ingress-nginx by Kubernetes
Listed below are 8 of the newest known vulnerabilities associated with "Ingress-nginx" by "Kubernetes".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2023-5044 json | Code injection via nginx.ingress.kubernetes.io/permanent-redirect annotation. | 8.8 - HIGH | 2023-10-25 | 2023-11-02 |
| CVE-2023-5043 json | Ingress nginx annotation injection causes arbitrary command execution. | 8.8 - HIGH | 2023-10-25 | 2023-11-02 |
| CVE-2022-4886 json | Ingress-nginx `path` sanitization can be bypassed with `log_format` directive. | 6.5 - MEDIUM | 2023-10-25 | 2023-11-02 |
| CVE-2021-25748 json | A security issue was discovered in ingress-nginx where a user that can create or update ingress objects can use a newline cha... | 6.5 - MEDIUM | 2023-05-24 | 2023-06-01 |
| CVE-2021-25746 json | A security issue was discovered in ingress-nginx where a user that can create or update ingress objects can use .metadata.ann... | 7.1 - HIGH | 2022-05-06 | 2022-12-02 |
| CVE-2021-25745 json | A security issue was discovered in ingress-nginx where a user that can create or update ingress objects can use the spec.rule... | 8.1 - HIGH | 2022-05-06 | 2022-12-02 |
| CVE-2021-25742 json | A security issue was discovered in ingress-nginx where a user that can create or update ingress objects can use the custom sn... | 7.1 - HIGH | 2021-10-29 | 2021-12-15 |
| CVE-2020-8553 json | The Kubernetes ingress-nginx component prior to version 0.28.0 allows a user with the ability to create namespaces and to rea... | 5.9 - MEDIUM | 2020-07-29 | 2020-08-04 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Kubernetes | Ingress-nginx | 0.9.6 | |||
| Application | Kubernetes | Ingress-nginx | 0.9.5 | |||
| Application | Kubernetes | Ingress-nginx | 0.9.4 | |||
| Application | Kubernetes | Ingress-nginx | 0.9.3 | |||
| Application | Kubernetes | Ingress-nginx | 0.9.2 | |||
| Application | Kubernetes | Ingress-nginx | 0.9.1 | |||
| Application | Kubernetes | Ingress-nginx | 0.9.0 | |||
| Application | Kubernetes | Ingress-nginx | 0.9.0 | |||
| Application | Kubernetes | Ingress-nginx | 0.9.0 | |||
| Application | Kubernetes | Ingress-nginx | 0.9.0 | |||
| Application | Kubernetes | Ingress-nginx | 0.9.0 | |||
| Application | Kubernetes | Ingress-nginx | 0.9.0 | |||
| Application | Kubernetes | Ingress-nginx | 0.9.0 | |||
| Application | Kubernetes | Ingress-nginx | 0.9.0 | |||
| Application | Kubernetes | Ingress-nginx | 0.9.0 | |||
| Application | Kubernetes | Ingress-nginx | 0.9.0 | |||
| Application | Kubernetes | Ingress-nginx | 0.9.0 | |||
| Application | Kubernetes | Ingress-nginx | 0.9.0 | |||
| Application | Kubernetes | Ingress-nginx | 0.9.0 | |||
| Application | Kubernetes | Ingress-nginx | 0.9.0 |