CVE-2025-24513
CVSS 3.1 Score 4.8 of 10 (medium)
Details
Published Mar 25, 2025
Updated: Mar 27, 2025
CWE ID 20
Summary
CVE-2025-24513 is a newly discovered vulnerability in the ingress-nginx component of Kubernetes (<https://github.com/kubernetes/ingress-nginx>). The issue lies in the Admission Controller feature, which inadvertently incorporates user-supplied data into filenames. This susceptibility can lead to directory traversal within the container, potentially causing denial-of-service attacks. In some cases, when combined with other vulnerabilities, it might also result in the disclosure of limited Secret objects from the cluster.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Kubernetes Ingress-nginx
Affected Vendors
- Kubernetes