'; } else{ echo ''; } echo '
|
|||
Release Date:2025/9/15
Rule Name:CVE-2025-1974,CVE-2025-1098:Kubernetes ingress-nginx Remte Code Execution Vulnerability
Severity:critical
CVE ID:CVE-2025-1974 CVE-2025-1098
Descripiton:
|
Kubernetes ingress-nginx is an open-source ingress controller for Kubernetes, released by the Cloud Native Computing Foundation (CNCF), and it uses NGINX as a reverse proxy and load balancer. There is a security vulnerability in Kubernetes ingress-nginx. This vulnerability stems from the fact that, under certain conditions, unauthenticated attackers can execute arbitrary code in the ingress-nginx controller environment by accessing the pod network, which may lead to the leakage of Secrets.This rule supports to defend the A6: Vulnerable and Outdated Components of OWASP Top 10 - 2021.
Other reference:None
Solution:
|
Update vendor patches.