CVE-2025-24513

CVSS 3.1 Score 4.8 of 10 (medium)

Details

Published Mar 25, 2025
Updated: Mar 27, 2025
CWE ID 20

Summary

CVE-2025-24513 is a newly discovered vulnerability in the ingress-nginx component of Kubernetes (<https://github.com/kubernetes/ingress-nginx>). The issue lies in the Admission Controller feature, which inadvertently incorporates user-supplied data into filenames. This susceptibility can lead to directory traversal within the container, potentially causing denial-of-service attacks. In some cases, when combined with other vulnerabilities, it might also result in the disclosure of limited Secret objects from the cluster.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Kubernetes Ingress-nginx

Affected Vendors

  • Kubernetes