CVE-2025-1097

CVSS 3.1 Score 8.8 of 10 (high)

Details

Published Mar 25, 2025
Updated: Mar 27, 2025
CWE ID 20

Summary

CVE-2025-1097 is a newly discovered vulnerability affecting the ingress-nginx component of Kubernetes (<https://github.com/kubernetes/ingress-nginx>). This issue arises from the misuse of the `auth-tls-match-cn` Ingress annotation, which allows the injection of configuration into nginx. Maliciously crafted inputs can lead to arbitrary code execution within the ingress-nginx controller, potentially granting unauthorized access to Secrets accessible to the controller in a default installation.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Kubernetes Ingress-nginx

Affected Vendors

  • Kubernetes