CVE-2025-24514

CVSS 3.1 Score 8.8 of 10 (high)

Details

Published Mar 25, 2025
Updated: Mar 27, 2025
CWE ID 20

Summary

CVE-2025-24514: A critical vulnerability was identified in the ingress-nginx component of Kubernetes, specifically in the `auth-url` Ingress annotation. By exploiting this issue, an attacker can inject malicious configuration into the nginx server, potentially resulting in arbitrary code execution within the ingress-nginx controller. Moreover, this vulnerability could lead to the disclosure of sensitive Secrets accessible to the controller, posing a significant risk to cluster security.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Kubernetes Ingress-nginx

Affected Vendors

  • Kubernetes