
Cloud Vulnerability DB
A community-led vulnerabilities database
A critical security vulnerability (CVE-2024-7646) was discovered in ingress-nginx, affecting versions prior to v1.11.2. The vulnerability allows actors with permission to create Ingress objects in the networking.k8s.io or extensions API group to bypass annotation validation, enabling arbitrary command injection and unauthorized access to ingress-nginx controller credentials. The issue was discovered and reported by André Storfjord Kristiansen, and has been assigned a High severity CVSS score of 8.8 (Kubernetes Issue, OSS Security).
The vulnerability stems from a flaw in the annotation validation process within ingress-nginx that allows malicious actors to bypass security controls. The issue received a CVSS v3.1 score of 8.8 (High) with the vector string CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H, indicating network accessibility, low attack complexity, and high impact on confidentiality, integrity, and availability. The vulnerability is classified as CWE-20 (Improper Input Validation) (Security Online, Kubernetes Issue).
In the default configuration, successful exploitation of this vulnerability provides access to all secrets within the Kubernetes cluster through the compromised ingress-nginx controller credentials. This poses a particularly significant risk in multi-tenant environments where non-admin users have permissions to create Ingress objects (Kubernetes Announce, Security Online).
The vulnerability can be exploited by creating Ingress objects with specially crafted annotations that contain carriage returns (\r). The attack requires network access and low complexity to execute, making it relatively straightforward for attackers with the necessary permissions to exploit (Kubernetes Issue, OSS Security).
The primary mitigation is to upgrade to ingress-nginx controller v1.11.2, which contains the security fixes implemented in PRs #11719 and #11721. Organizations should also review their Kubernetes audit logs for Ingress objects with annotations (particularly nginx.ingress.kubernetes.io/auth-tls-verify-client) containing carriage returns, as these may indicate exploitation attempts (Kubernetes Issue, Security Online).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."