We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.
Please see our statement on Data Privacy.
A security issue was discovered in ingress-nginx https://github.com/kubernetes/ingress-nginx where attacker-provided data are included in a filename by the ingress-nginx Admission Controller feature, resulting in directory traversal within the container. This could result in denial of service, or when combined with other vulnerabilities, limited disclosure of Secret objects from the cluster.
Reserved 2025-01-23 | Published 2025-03-24 | Updated 2025-03-25 | Assigner kubernetesCWE-20 Improper Input Validation
Nir Ohfeld
Ronen Shustin
github.com/kubernetes/kubernetes/issues/131005
Support options