🔍 Search Results

Searching CVE for "nginx"

100 result(s)
CVE-2026-27944 CRITICAL 9.8

Nginx UI versions before 2.3.3 expose an unauthenticated API endpoint that discloses encryption keys in response headers, allowing attackers to download and decrypt full system backups containing sens...

Published: Mar 5, 2026

CVE-2026-27630 HIGH 7.5

TinyWeb versions before 2.02 are vulnerable to Slowloris denial-of-service attacks where attackers can exhaust server resources by opening many connections and sending data extremely slowly. Anyone ho...

Published: Feb 26, 2026

CVE-2026-25739 MEDIUM 5.4

This CVE describes a cross-site scripting (XSS) vulnerability in Indico event management system versions prior to 3.3.10. Attackers can inject malicious scripts by uploading certain file types as mate...

Published: Feb 19, 2026

CVE-2026-2145 LOW 3.5

This vulnerability allows attackers to inject malicious scripts via the nginxDir parameter in the nginxWebUI web management interface. When exploited, it enables cross-site scripting attacks that can ...

Published: Feb 8, 2026

CVE-2025-15566 HIGH 8.8

This CVE allows attackers to inject malicious configuration into ingress-nginx via the auth-proxy-set-headers annotation, potentially leading to arbitrary code execution and disclosure of Kubernetes S...

Published: Feb 6, 2026

CVE-2026-1642 MEDIUM 5.9

A vulnerability in NGINX OSS and NGINX Plus allows attackers in a man-in-the-middle position on the upstream server side to inject plain text data into responses from proxied TLS servers. This affects...

Published: Feb 4, 2026

CVE-2026-24513 LOW 3.1

This CVE describes an authentication bypass vulnerability in ingress-nginx when using custom error backends. If administrators configure a defective custom error backend that doesn't respect the X-Cod...

Published: Feb 3, 2026

CVE-2026-24514 MEDIUM 6.5

This CVE describes a denial-of-service vulnerability in ingress-nginx's validating admission controller. Attackers can send large requests to exhaust memory, potentially causing the controller pod to ...

Published: Feb 3, 2026

CVE-2026-1580 HIGH 8.8

This vulnerability in ingress-nginx allows attackers to inject malicious configuration via the auth-method annotation, leading to arbitrary code execution within the controller pod. This could result ...

Published: Feb 3, 2026

CVE-2026-24512 HIGH 8.8

This CVE describes a configuration injection vulnerability in ingress-nginx where attackers can inject malicious nginx configuration through the `rules.http.paths.path` field. This allows arbitrary co...

Published: Feb 3, 2026

CVE-2026-23837 CRITICAL 9.8

CVE-2026-23837 is an authentication bypass vulnerability in MyTube that allows unauthenticated attackers to access protected administrative functions. All users running MyTube with loginEnabled: true ...

Published: Jan 19, 2026

CVE-2026-23838

Tandoor Recipes' default NixOS configuration exposes the SQLite database file externally when using SQLite with default MEDIA_ROOT settings. This allows unauthenticated attackers to download the entir...

Published: Jan 19, 2026

CVE-2026-22265 HIGH 7.5

CVE-2026-22265 is a command injection vulnerability in Roxy-WI web interface versions prior to 8.2.8.2 that allows authenticated users to execute arbitrary system commands through the log viewing func...

Published: Jan 15, 2026

CVE-2025-62126 MEDIUM 5.3

This vulnerability in the Varnish/Nginx Proxy Caching WordPress plugin allows attackers to retrieve sensitive information embedded in cached data. It affects all WordPress sites using this plugin up t...

Published: Dec 31, 2025

CVE-2025-14727 HIGH 8.3

A vulnerability in NGINX Ingress Controller's nginx.org/rewrite-target annotation validation allows path traversal attacks. This affects Kubernetes clusters using NGINX Ingress Controller with the vul...

Published: Dec 17, 2025

CVE-2025-67731

Servify Express versions before 1.2 have a denial-of-service vulnerability where attackers can send extremely large JSON request bodies, causing excessive memory usage, degraded performance, or proces...

Published: Dec 12, 2025

CVE-2025-66491 MEDIUM 5.9

Traefik versions 3.5.0 through 3.6.2 have inverted TLS verification logic in the nginx.ingress.kubernetes.io/proxy-ssl-verify annotation. Setting the annotation to 'on' (intending to enable backend TL...

Published: Dec 9, 2025

CVE-2025-66577 MEDIUM 5.3

This vulnerability in cpp-httplib allows attackers to spoof client IP addresses by sending malicious X-Forwarded-For or X-Real-IP headers. This can poison server logs, evade audit trails, and potentia...

Published: Dec 5, 2025

CVE-2025-66570 CRITICAL 10.0

This vulnerability in cpp-httplib allows attackers to inject HTTP headers (REMOTE_ADDR, REMOTE_PORT, LOCAL_ADDR, LOCAL_PORT) that shadow server-generated metadata. This enables IP spoofing, log poison...

Published: Dec 5, 2025

CVE-2025-11379 MEDIUM 5.3

The WebP Express WordPress plugin exposes configuration data through predictable config file names on NGINX servers. Unauthenticated attackers can access sensitive configuration information. All WordP...

Published: Dec 4, 2025

CVE-2025-13516 HIGH 8.1

The SureMail WordPress plugin allows unauthenticated attackers to upload malicious PHP files through public forms that email attachments, leading to remote code execution. This affects WordPress sites...

Published: Dec 2, 2025

CVE-2025-66206 MEDIUM 6.8

This CVE describes a path traversal vulnerability in Frappe web framework that allows attackers to retrieve arbitrary files from the server if the full path is known. It affects direct deployments usi...

Published: Dec 1, 2025

CVE-2025-10579 MEDIUM 5.3

The BackWPup WordPress plugin up to version 5.5.0 has an authorization vulnerability where authenticated users with Subscriber-level access or higher can retrieve backup filenames during backup operat...

Published: Oct 25, 2025

CVE-2025-12014 MEDIUM 4.3

This vulnerability allows authenticated WordPress users with Subscriber-level access or higher to modify the NGINX Cache Optimizer plugin's blacklist settings without proper authorization. Attackers c...

Published: Oct 24, 2025

CVE-2025-58474 MEDIUM 5.3

This vulnerability affects BIG-IP Advanced WAF with SSRF protection or NGINX with App Protect Bot Defense, where undisclosed requests can disrupt new client connections. It causes denial of service by...

Published: Oct 15, 2025

CVE-2025-61925 MEDIUM 6.5

Astro web framework versions before 5.14.2 reflect unvalidated X-Forwarded-Host header values in Astro.url output, allowing attackers to manipulate URLs used for canonical links, login forms, or other...

Published: Oct 10, 2025

CVE-2025-61780 MEDIUM 5.8

This vulnerability allows attackers to bypass proxy-level access restrictions in Rack applications using Rack::Sendfile with certain proxy configurations. By sending crafted x-sendfile-type and x-acce...

Published: Oct 10, 2025

CVE-2025-61772 HIGH 7.5

This vulnerability in Rack's multipart parser allows remote attackers to cause denial of service by sending incomplete multipart headers that trigger unbounded memory accumulation. All Ruby web applic...

Published: Oct 7, 2025

CVE-2025-59951 CRITICAL 9.1

A critical authentication bypass vulnerability in Termix versions 1.5.0 and below allows unauthenticated attackers to access the /ssh/db/host/internal endpoint, exposing stored SSH host information in...

Published: Oct 1, 2025

CVE-2025-34203 CRITICAL 9.8

Vasion Print (formerly PrinterLogic) contains outdated, end-of-life third-party components across multiple Docker containers, creating a large attack surface. Attackers can chain vulnerabilities in th...

Published: Sep 19, 2025

CVE-2023-53382 MEDIUM 5.5

A NULL pointer dereference vulnerability in the Linux kernel's SMC (Shared Memory Communications) subsystem allows local attackers to cause a kernel panic and system crash. This affects systems using ...

Published: Sep 18, 2025

CVE-2025-58362 HIGH 7.5

This vulnerability in Hono web framework versions 4.8.0 through 4.9.5 allows path confusion attacks that could bypass proxy-level access controls like Nginx location blocks. Attackers could potentiall...

Published: Sep 5, 2025

CVE-2025-58048 CRITICAL 9.9

This vulnerability allows authenticated users in Paymenter webshop software to upload arbitrary files through ticket attachments. Attackers can exploit this to extract sensitive data, read credentials...

Published: Aug 28, 2025

CVE-2025-55740 MEDIUM 6.5

This CVE describes a configuration vulnerability in nginx-defender where default administrative credentials are present in example configuration files. Attackers with network access can use these defa...

Published: Aug 19, 2025

CVE-2025-50579 MEDIUM 5.3

A CORS misconfiguration in Nginx Proxy Manager v2.12.3 allows unauthorized domains to access sensitive data like JWT tokens due to improper Origin header validation. Attackers can intercept tokens usi...

Published: Aug 19, 2025

CVE-2025-5961 HIGH 7.2

The WPvivid Backup & Migration WordPress plugin allows authenticated administrators to upload arbitrary files due to missing file type validation. This vulnerability can lead to remote code execution ...

Published: Jul 3, 2025

CVE-2025-52891 MEDIUM 6.5

This vulnerability in ModSecurity causes a segmentation fault when processing XML requests containing empty tags, leading to denial of service. It affects ModSecurity installations with SecParseXmlInt...

Published: Jul 2, 2025

CVE-2024-47056 MEDIUM 5.1

This vulnerability allows unauthenticated attackers to directly access Mautic's .env configuration files via web browser, exposing sensitive information like database credentials and API keys. It affe...

Published: May 28, 2025

CVE-2025-47942 MEDIUM 5.3

The Open edX Platform allows unauthorized users to download python_lib.zip files from courses, which may contain custom grading code or answers to course problems. This affects any Open edX deployment...

Published: May 21, 2025

CVE-2025-47947 HIGH 7.5

ModSecurity versions up to 2.9.8 are vulnerable to a denial-of-service attack when processing JSON payloads with specific rule configurations. Attackers can crash the WAF by sending specially crafted ...

Published: May 21, 2025

CVE-2025-46727 HIGH 7.5

This vulnerability in Rack's query parser allows attackers to send HTTP requests with extremely large numbers of parameters, causing memory exhaustion and CPU resource consumption. This leads to denia...

Published: May 7, 2025

CVE-2023-53110 MEDIUM 5.5

A race condition vulnerability in the Linux kernel's SMC-R (Shared Memory Communications over RDMA) implementation allows a NULL pointer dereference when terminating network connections under stress c...

Published: May 2, 2025

CVE-2025-2787 HIGH 8.8

This vulnerability in KNIME Business Hub's ingress-nginx component allows authenticated attackers to potentially execute arbitrary code within the Kubernetes cluster. It affects all KNIME Business Hub...

Published: Mar 26, 2025

CVE-2025-24514 HIGH 8.8

This vulnerability allows attackers to inject malicious configuration into ingress-nginx via the auth-url annotation, leading to arbitrary code execution within the controller pod. It affects all Kube...

Published: Mar 25, 2025

CVE-2025-1098 HIGH 8.8

This vulnerability in ingress-nginx allows attackers to inject arbitrary nginx configuration via the 'mirror-target' and 'mirror-host' annotations, potentially leading to remote code execution and dis...

Published: Mar 25, 2025

CVE-2025-1974 CRITICAL 9.8

CVE-2025-1974 is a critical vulnerability in Kubernetes' ingress-nginx controller that allows unauthenticated attackers on the pod network to execute arbitrary code with the controller's privileges. T...

Published: Mar 25, 2025

CVE-2025-24513 MEDIUM 4.8

A directory traversal vulnerability in ingress-nginx's Admission Controller allows attackers to manipulate filenames to access files outside intended directories. This affects Kubernetes clusters usin...

Published: Mar 25, 2025

CVE-2025-1097 HIGH 8.8

CVE-2025-1097 is a critical vulnerability in ingress-nginx where the auth-tls-match-cn annotation can be exploited to inject malicious configuration into nginx, potentially leading to arbitrary code e...

Published: Mar 25, 2025

CVE-2025-1695 MEDIUM 5.3

This vulnerability in NGINX Unit with the Java Language Module allows remote attackers to send specific requests that trigger an infinite loop, causing high CPU usage and potential denial-of-service. ...

Published: Mar 4, 2025

CVE-2022-49698 HIGH 7.8

This CVE addresses a race condition in the Linux kernel's netfilter subsystem where using prandom in preemptible contexts could cause kernel bugs. The vulnerability affects Linux systems using nftable...

Published: Feb 26, 2025

CVE-2025-23419 MEDIUM 4.3

This CVE describes a client certificate authentication bypass vulnerability in nginx when multiple server blocks share the same IP/port. Attackers can exploit TLS session resumption to bypass client c...

Published: Feb 5, 2025

CVE-2025-23001 MEDIUM 6.1

A Host header injection vulnerability in CTFd 3.7.5 allows attackers to manipulate the Host header in HTTP requests. This can lead to phishing attacks, password reset hijacking, or cache poisoning. Af...

Published: Jan 31, 2025

CVE-2024-56236 MEDIUM 4.3

This CVE describes a Missing Authorization vulnerability in the Hestia Nginx Cache WordPress plugin that allows attackers to exploit incorrectly configured access control security levels. Attackers ca...

Published: Jan 2, 2025

CVE-2024-53991 HIGH 7.5

This vulnerability allows attackers to download Discourse backup files through nginx misconfiguration when using local storage. Only Discourse instances configured with FileStore::LocalStore for uploa...

Published: Dec 19, 2024

CVE-2024-10590 HIGH 8.8

The Opt-In Downloads WordPress plugin allows authenticated attackers with Subscriber-level access or higher to upload arbitrary files due to missing file type validation. This vulnerability can lead t...

Published: Dec 12, 2024

CVE-2024-10318 MEDIUM 5.4

A session fixation vulnerability in NGINX OpenID Connect reference implementation allows attackers to bind a victim's session to an attacker-controlled account by exploiting missing nonce validation d...

Published: Nov 6, 2024

CVE-2024-49366 HIGH 7.5

Nginx UI v2.0.0-beta.35 and earlier contains a path traversal vulnerability that allows attackers to write arbitrary files to the server by manipulating JSON input with '../../' sequences. This can le...

Published: Oct 21, 2024

CVE-2024-49368 CRITICAL 9.8

CVE-2024-49368 is a critical command injection vulnerability in Nginx UI that allows attackers to execute arbitrary commands on the server. This affects all Nginx UI installations prior to version 2.0...

Published: Oct 21, 2024

CVE-2024-46256 CRITICAL 9.8

This CVE describes a command injection vulnerability in NginxProxyManager's Let's Encrypt certificate request function. An attacker can execute arbitrary commands on the server with the privileges of ...

Published: Sep 27, 2024

CVE-2024-45614 MEDIUM 5.4

This vulnerability in Puma web server allows clients to override proxy-set headers like X-Forwarded-For by sending underscore versions (X-Forwarded_For). This affects any users relying on proxy header...

Published: Sep 19, 2024

CVE-2024-7646 HIGH 8.8

This vulnerability allows attackers with permission to create Ingress objects to bypass annotation validation and execute arbitrary commands, potentially compromising the ingress-nginx controller cred...

Published: Aug 16, 2024

CVE-2024-7347 MEDIUM 4.7

This vulnerability in NGINX's ngx_http_mp4_module allows attackers to cause memory over-read and worker process termination by uploading specially crafted MP4 files. Only NGINX installations built wit...

Published: Aug 14, 2024

CVE-2024-41668 HIGH 8.3

This CVE describes a Server-Side Request Forgery (SSRF) vulnerability in cBioPortal's proxy endpoint. Unauthenticated attackers can exploit publicly exposed instances, while authenticated users can ex...

Published: Jul 23, 2024

CVE-2024-39935 HIGH 8.8

CVE-2024-39935 is an OS command injection vulnerability in jc21 NGINX Proxy Manager that allows authenticated users with certificate management privileges to execute arbitrary commands on the host sys...

Published: Jul 4, 2024

CVE-2022-48751 MEDIUM 4.7

A race condition vulnerability in the Linux kernel's SMC (Shared Memory Communications) subsystem allows NULL pointer dereference when accessing a released socket. This can cause kernel crashes (denia...

Published: Jun 20, 2024

CVE-2024-32760 MEDIUM 6.5

This vulnerability in NGINX Plus and NGINX OSS allows attackers to cause denial of service by sending specially crafted HTTP/3 requests when the QUIC module is enabled. The worker processes may termin...

Published: May 29, 2024

CVE-2024-35200 MEDIUM 5.3

This vulnerability allows attackers to cause denial of service by sending specially crafted HTTP/3 requests to NGINX servers configured with the QUIC module. When exploited, NGINX worker processes ter...

Published: May 29, 2024

CVE-2023-39481 HIGH 8.8

This vulnerability allows authenticated remote attackers to execute arbitrary code as root on Softing Secure Integration Server installations. The flaw stems from an inconsistency in URI parsing betwe...

Published: May 3, 2024

CVE-2024-3738 HIGH 7.3

This critical vulnerability in cym1102 nginxWebUI allows remote attackers to bypass certificate validation through manipulation of the nginxPath parameter in the handlePath function. This could lead t...

Published: Apr 13, 2024

CVE-2024-28101 HIGH 7.5

The Apollo Router versions 0.9.5 through 1.40.1 have a DoS vulnerability where highly compressed HTTP payloads cause excessive memory consumption during decompression before size limits are enforced. ...

Published: Mar 21, 2024

CVE-2024-24989 HIGH 7.5

This vulnerability allows attackers to cause denial of service by sending specially crafted requests to NGINX servers with HTTP/3 QUIC module enabled. It affects NGINX Plus and NGINX OSS when configur...

Published: Feb 14, 2024

CVE-2024-23828 HIGH 8.8

This vulnerability allows authenticated attackers to execute arbitrary commands on Nginx-UI servers via CRLF injection when modifying test_config_cmd or start_cmd parameters. It affects all Nginx-UI i...

Published: Jan 29, 2024

CVE-2024-23827 CRITICAL 9.8

CVE-2024-23827 is a critical path traversal vulnerability in Nginx-UI's Import Certificate feature that allows attackers to write arbitrary files to the system. This can lead to remote code execution ...

Published: Jan 29, 2024

CVE-2023-50919 CRITICAL 9.8

This CVE describes an NGINX authentication bypass vulnerability in GL.iNet router firmware that allows unauthenticated attackers to execute arbitrary commands. The flaw exists in Lua string pattern ma...

Published: Jan 12, 2024

CVE-2024-22196 HIGH 7.0

CVE-2024-22196 is a SQL injection vulnerability in Nginx-UI where user-controlled 'order' and 'sort_by' query parameters are appended to SQL queries without sanitization. This allows attackers to exec...

Published: Jan 11, 2024

CVE-2024-22197 HIGH 7.7

This vulnerability in nginx-ui allows authenticated users to modify critical nginx configuration commands via API endpoints that should be restricted, potentially leading to remote code execution, pri...

Published: Jan 11, 2024

CVE-2023-5043 HIGH 7.6

This CVE allows attackers to inject malicious annotations into Ingress nginx configurations, leading to arbitrary command execution on the host system. It affects Kubernetes clusters using ingress-ngi...

Published: Oct 25, 2023

CVE-2022-4886 HIGH 8.8

This vulnerability allows attackers to bypass path sanitization in ingress-nginx by using the log_format directive, potentially enabling path traversal attacks. It affects Kubernetes ingress-nginx dep...

Published: Oct 25, 2023

CVE-2023-44388 HIGH 7.5

CVE-2023-44388 is a denial-of-service vulnerability in Discourse where malicious requests can rapidly fill production log files, causing servers to run out of disk space. This affects all Discourse ad...

Published: Oct 16, 2023

CVE-2023-45132 CRITICAL 9.1

This vulnerability allows attackers to bypass NAXSI web application firewall protection when malicious X-Forwarded-For headers match IgnoreIP or IgnoreCIDR rules. It affects NAXSI WAF installations ru...

Published: Oct 11, 2023

CVE-2023-42457 HIGH 7.5

This CVE describes a denial-of-service vulnerability in plone.rest where repeated use of the `++api++` traverser in URLs causes increasing processing time, making the server less responsive. It affect...

Published: Sep 21, 2023

CVE-2020-21699 HIGH 7.5

CVE-2020-21699 is an integer overflow vulnerability in Tengine's range filter module that allows attackers to leak potentially sensitive information from web servers. The vulnerability affects Tengine...

Published: Aug 22, 2023

CVE-2023-4334 HIGH 7.5

The Broadcom RAID Controller Web server (nginx) exposes private files without requiring authentication. This vulnerability allows unauthorized users to access sensitive system files. Organizations usi...

Published: Aug 15, 2023

CVE-2023-28656 HIGH 8.1

CVE-2023-28656 is an authorization bypass vulnerability in NGINX Management Suite that allows authenticated users to access configuration objects outside their assigned environment boundaries. This af...

Published: May 3, 2023

CVE-2023-27728 HIGH 7.5

This vulnerability in Nginx NJS v0.7.10 allows attackers to trigger a segmentation violation via the njs_dump_is_recursive function, potentially causing denial of service or arbitrary code execution. ...

Published: Apr 9, 2023

CVE-2023-27730 HIGH 7.5

CVE-2023-27730 is a memory corruption vulnerability in Nginx NJS JavaScript engine that can cause segmentation faults via the njs_lvlhsh_find function. This affects systems running Nginx with NJS modu...

Published: Apr 9, 2023

CVE-2023-27224 CRITICAL 9.8

CVE-2023-27224 is a command injection vulnerability in Nginx Proxy Manager v2.9.19 that allows attackers to execute arbitrary code via malicious Lua scripts in configuration files. This affects all us...

Published: Mar 22, 2023

CVE-2023-25803 HIGH 7.5

CVE-2023-25803 is a directory traversal vulnerability in Roxy-WI web interface that allows attackers to read arbitrary server-side files. This affects all Roxy-WI installations prior to version 6.3.5....

Published: Mar 13, 2023

CVE-2022-34028 HIGH 7.5

CVE-2022-34028 is a segmentation fault vulnerability in Nginx NJS JavaScript engine that occurs when processing malformed UTF-8 sequences. This vulnerability could allow attackers to crash Nginx proce...

Published: Jul 18, 2022

CVE-2022-34029 CRITICAL 9.1

CVE-2022-34029 is an out-of-bounds read vulnerability in Nginx NJS (JavaScript engine) that could allow attackers to read sensitive memory contents or cause denial of service. This affects systems run...

Published: Jul 18, 2022

CVE-2022-34031 HIGH 7.5

CVE-2022-34031 is a segmentation violation vulnerability in Nginx NJS JavaScript engine that could allow attackers to crash the Nginx process or potentially execute arbitrary code. This affects system...

Published: Jul 18, 2022

CVE-2022-31161 CRITICAL 10.0

CVE-2022-31161 is a critical remote code execution vulnerability in Roxy-WI web interface versions prior to 6.1.1.0. It allows unauthenticated attackers to execute arbitrary system commands via the su...

Published: Jul 15, 2022

CVE-2022-31137 CRITICAL 10.0

CVE-2022-31137 is a critical remote code execution vulnerability in Roxy-WI web interface that allows unauthenticated attackers to execute arbitrary system commands. The vulnerability exists in the su...

Published: Jul 8, 2022

CVE-2022-31125 CRITICAL 10.0

CVE-2022-31125 is an authentication bypass vulnerability in Roxy-wi web interface that allows unauthenticated remote attackers to access administrative functionality. This affects all Roxy-wi installa...

Published: Jul 6, 2022

CVE-2022-31081 HIGH 7.3

CVE-2022-31081 is an HTTP request smuggling vulnerability in HTTP::Daemon Perl library versions before 6.15. It allows attackers to bypass security controls, poison caches, or gain unauthorized API ac...

Published: Jun 27, 2022

CVE-2022-29169 HIGH 7.5

BigBlueButton web conferencing systems are vulnerable to regular expression denial of service (ReDoS) attacks through malicious User-Agent headers. Attackers can send specially crafted requests contai...

Published: Jun 1, 2022

CVE-2022-29379 CRITICAL 9.8

This CVE describes a stack overflow vulnerability in Nginx NJS module loader that could allow remote code execution or denial of service. However, multiple sources dispute this affects released versio...

Published: May 25, 2022

CVE-2022-29588 HIGH 7.5

Konica Minolta bizhub MFP devices store administrative passwords in cleartext files, allowing attackers with local access to read sensitive credentials. This affects all Konica Minolta bizhub MFP devi...

Published: May 16, 2022

CVE-2022-29369 HIGH 7.5

CVE-2022-29369 is a segmentation fault vulnerability in Nginx NJS (JavaScript engine) that can cause denial of service or potentially allow arbitrary code execution. It affects systems running Nginx w...

Published: May 12, 2022

CVE-2021-25745 HIGH 7.6

CVE-2021-25745 is a vulnerability in ingress-nginx where users with permissions to create or update Ingress objects can exploit the path field to obtain the controller's credentials. These credentials...

Published: May 6, 2022