Ingress-Nginx is a widely used Ingress controller for Kubernetes, used to manage external access to services within a cluster. A critical security vulnerability has been identified in certain versions of Ingress-Nginx, which allows for remote code execution (RCE) via malicious annotations. This vulnerability is being actively exploited and poses a significant risk to Kubernetes environments.
| Date | 2025-03-27 14:22:23 |
| Information |
|
Technical Summary
The vulnerability is associated with the Ingress auth-tls-match-cn annotation, which allows an attacker to inject arbitrary Nginx configuration directives. This configuration flaw can be exploited to load malicious modules or execute arbitrary commands within the context of the Ingress-Nginx controller.
By sending a specially crafted request, an attacker can modify the Nginx configuration using an annotation such as:
nginx.ingress.kubernetes.io/auth-url: "http://example.com#;load_module test;\n"
This exploit allows for unauthorized code execution, leading to the complete compromise of the Ingress-Nginx controller. Furthermore, attackers can potentially access all Kubernetes Secrets present in the cluster, enabling privilege escalation and full takeover of the cluster.
Recommendations
To mitigate this vulnerability, administrators should act immediately:
Update Ingress-Nginx: Upgrade to one of the following patched versions:
- Version 1.12.1 or later
- Version 1.11.5 or later
Restrict Annotations: Implement policies to prevent the application of unauthorized annotations to Ingress resources.
Limit Controller Permissions: Ensure that the Ingress-Nginx controller does not have unnecessary access to sensitive Kubernetes resources.
Monitor for Exploitation Attempts: Analyze logs for suspicious modifications to Ingress resources or unauthorized changes to the Nginx configuration.
Apply Network Security Measures: Limit external access to the Ingress controller and apply strict firewall rules.
Protect your organisation with Threat Intelligence and Digital Risk Protection.
Choose ISGroup for a practical, tailored engagement:
- A focused assessment of your environment and requirements
- Clear findings with a prioritised, actionable roadmap
- Direct support from experienced specialists through remediation and implementation
