Improper Input Validation
CVE-2025-1097
Summary
A security issue was discovered in ingress-nginx, where the `auth-tls-match-cn` Ingress annotation can be used to inject configuration into nginx. This can lead to arbitrary code execution in the context of the ingress-nginx controller and disclosure of secrets accessible to the controller. This issue affects github.com/kubernetes/ingress-nginx versions prior to v1.11.5 and v1.12.x prior to v1.12.1.
- LOW
- NETWORK
- HIGH
- UNCHANGED
- NONE
- LOW
- HIGH
- HIGH
CWE-20 - Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
References
Advisory Timeline
- Published