Database/Container, Kubernetes & orchestration
ingress-nginx: Custom nginx snippets in an Ingress annotation retrieve the ingress-nginx service-account token
CVSS 7.6CVE-2021-25742Container, Kubernetes & orchestrationcurated
Impact
Custom nginx snippets in an Ingress annotation retrieve the ingress-nginx service-account token and therefore every Secret in the cluster
Who can reach it
Cluster user with namespace access who can create Ingress objects
What to do
Rolling controller upgrade and set allow-snippet-annotations: false; rotate all cluster Secrets if exploited
References
Related entries
- ingress-nginx: Ingress `path` can be pointed at the service-account token fileCVE-2021-25745 · ingress-nginxHigh
- ingress-nginx: Directive injection through Ingress annotations obtains controller credentialsCVE-2021-25746 · ingress-nginxHigh
- ingress-nginx: Newline character bypasses `path` sanitizationCVE-2021-25748 · ingress-nginxHigh
- ingress-nginx: Annotation injection causes arbitrary command execution in the controller podCVE-2023-5043 · ingress-nginxHigh
- ingress-nginx: Code injection via the permanent-redirect annotationCVE-2023-5044 · ingress-nginxHigh
- ingress-nginx: Admission controller denial of serviceCVE-2026-24514 · ingress-nginxMedium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.