Description
A vulnerability exists in NGINX Ingress Controller's nginx.org/rewrite-target annotation validation. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Problem types
CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Product status
5.3.0 (custom) before 5.3.1
5.2.0 (custom) before *
5.1.0 (custom) before *
5.0.0 (custom) before *
4.0.0 (custom) before *
3.0.0 (custom) before *
Credits
F5 acknowledges Ricardo Katz of Red Hat for bringing this issue to our attention and following the highest standards of coordinated disclosure.
References
my.f5.com/manage/s/article/K000158176
Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.