CVE-2025-1097
CVSS 3.1 Score 8.8 of 10 (high)
Details
Published Mar 25, 2025
Updated: Mar 27, 2025
CWE ID 20
Summary
CVE-2025-1097 is a newly discovered vulnerability affecting the ingress-nginx component of Kubernetes (<https://github.com/kubernetes/ingress-nginx>). This issue arises from the misuse of the `auth-tls-match-cn` Ingress annotation, which allows the injection of configuration into nginx. Maliciously crafted inputs can lead to arbitrary code execution within the ingress-nginx controller, potentially granting unauthorized access to Secrets accessible to the controller in a default installation.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Kubernetes Ingress-nginx
Affected Vendors
- Kubernetes