We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2025-24513

ingress-nginx controller - auth secret file path traversal vulnerability



Description

A security issue was discovered in ingress-nginx https://github.com/kubernetes/ingress-nginx where attacker-provided data are included in a filename by the ingress-nginx Admission Controller feature, resulting in directory traversal within the container. This could result in denial of service, or when combined with other vulnerabilities, limited disclosure of Secret objects from the cluster.

Reserved 2025-01-23 | Published 2025-03-24 | Updated 2025-03-25 | Assigner kubernetes


MEDIUM: 4.8CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L

Problem types

CWE-20 Improper Input Validation

Product status

Default status
unaffected

Any version
affected

1.12.0
affected

Credits

Nir Ohfeld finder

Ronen Shustin finder

References

github.com/kubernetes/kubernetes/issues/131005

cve.org (CVE-2025-24513)

nvd.nist.gov (CVE-2025-24513)

Download JSON

Share this page
https://cve.threatint.eu/CVE/CVE-2025-24513

Support options

Helpdesk Chat, Email, Knowledgebase