CVE-2024-7646 is a high-severity vulnerability affecting ingress-nginx, allowing an attacker with Ingress object creation permissions to bypass annotation validation. This bypass enables arbitrary command injection, leading to the compromise of the ingress-nginx controller's credentials, which, by default, grants access to all cluster secrets. With a CVSS score of 8.8 (HIGH), the vulnerability is network-exploitable with low privileges and no user interaction, resulting in high confidentiality, integrity, and availability impacts. While there is no known active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), the vulnerability has garnered some community discussion, indicating awareness within the cybersecurity community.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0, < 1.10.4CPE match | cpe:2.3:a:kubernetes:ingress-nginx:*:*:*:*:*:*:*:* | ||
>= 1.11.0, < 1.11.2CPE match | cpe:2.3:a:kubernetes:ingress-nginx:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Ingress-nginx Annotation Validation Bypass
Ingress-nginx Annotation Validation Bypass
Ingress-nginx Annotation Validation Bypass
Ingress-nginx Annotation Validation Bypass