Upstream information
Description
A security issue was discovered in ingress-nginx https://github.com/kubernetes/ingress-nginx where attacker-provided data are included in a filename by the ingress-nginx Admission Controller feature, resulting in directory traversal within the container. This could result in denial of service, or when combined with other vulnerabilities, limited disclosure of Secret objects from the cluster.SUSE information
Overall state of this security issue: Resolved
This issue is currently rated as having moderate severity.
CNA (Kubernetes) | |
---|---|
Base Score | 4.8 |
Vector | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L |
Attack Vector | Network |
Attack Complexity | High |
Privileges Required | None |
User Interaction | None |
Scope | Unchanged |
Confidentiality Impact | Low |
Integrity Impact | None |
Availability Impact | Low |
CVSSv3 Version | 3.1 |
SUSE Security Advisories:
- TID000021756, published Tue Mar 25 14:56:36 CET 2025
- TID000021757, published Thu Mar 27 06:56:01 CET 2025
- openSUSE-SU-2025:14937-1, published Sat Mar 29 18:50:22 2025
List of released packages
Product(s) | Fixed package version(s) | References |
---|---|---|
openSUSE Tumbleweed |
| Patchnames: openSUSE-Tumbleweed-2025-14937 |
SUSE Timeline for this CVE
CVE page created: Mon Mar 24 21:00:08 2025CVE page last modified: Sat Mar 29 20:05:25 2025