Upstream information
Description
A security issue was discovered in Kubernetes where under certain conditions, an unauthenticated attacker with access to the pod network can achieve arbitrary code execution in the context of the ingress-nginx controller. This can lead to disclosure of Secrets accessible to the controller. (Note that in the default installation, the controller can access all Secrets cluster-wide.)SUSE information
Overall state of this security issue: Resolved
This issue is currently rated as having critical severity.
CNA (Kubernetes) | |
---|---|
Base Score | 9.8 |
Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Attack Vector | Network |
Attack Complexity | Low |
Privileges Required | None |
User Interaction | None |
Scope | Unchanged |
Confidentiality Impact | High |
Integrity Impact | High |
Availability Impact | High |
CVSSv3 Version | 3.1 |
SUSE Security Advisories:
- TID000021756, published Tue Mar 25 14:56:36 CET 2025
- TID000021757, published Thu Mar 27 06:56:01 CET 2025
- openSUSE-SU-2025:14937-1, published Sat Mar 29 18:50:22 2025
- openSUSE-SU-2025:14941-1, published Sat Mar 29 18:50:22 2025
- openSUSE-SU-2025:14942-1, published Sat Mar 29 18:50:22 2025
- openSUSE-SU-2025:14943-1, published Sat Mar 29 18:50:22 2025
- openSUSE-SU-2025:14944-1, published Sat Mar 29 18:50:22 2025
List of released packages
Product(s) | Fixed package version(s) | References |
---|---|---|
openSUSE Tumbleweed |
| Patchnames: openSUSE-Tumbleweed-2025-14937 openSUSE-Tumbleweed-2025-14941 openSUSE-Tumbleweed-2025-14942 openSUSE-Tumbleweed-2025-14943 openSUSE-Tumbleweed-2025-14944 |
SUSE Timeline for this CVE
CVE page created: Mon Mar 24 21:00:08 2025CVE page last modified: Sat Mar 29 20:04:39 2025