CVE-2025-1974

Kubernetes Ingress-nginx Remote Code Execution Vulnerability (CVE-2025-1974)

março 27, 2025

Overview Recently, NSFOCUS CERT detected that Kubernetes issued a security announcement and fixed the Kubernetes Ingress-nginx remote code execution vulnerability (CVE-2025-1974). The Ingress controller deployed in Kubernetes Pod can be accessed through the network without authentication. When the Admission webhook is open, an unauthenticated attacker can remotely inject any nginx configuration by sending a special […]

Search

Inscreva-se no Blog da NSFOCUS