Vulnerabilities in ingress-nginx that can compromise Kubernetes clusters
Three vulnerabilities have been identified in the developing Kubernetes ingress controller ingress-nginx that allow access to the Ingress object settings in the default configuration, which, among other things, store the credentials for accessing Kubernetes servers, enabling privileged access to the cluster. These issues only affect the ingress-nginx controller from the Kubernetes project and do not impact the kubernetes-ingress controller being developed by […]
