Live data from Hacker News

Three new Nginx ingress controller vulnerabilities and the affect on Kubernetes

armosec.io

1–2 of 2 posts

Re: Three new Nginx ingress controller vulnerabilities and the affect on Kubernetes

#2
CVE-2023-5043, CVE-2023-5044 and CVE-2022-4886 can be exploited by attacker to steal secret credentials from K8s cluster. Three security issues were reported on October 27th by the Kubernetes security community, all of them related to the popular NGINX ingress component.