Improper Input Validation Affecting k8s.io/ingress-nginx/internal/ingress/annotations/authtls package, versions <1.10.4 >=1.11.0 <1.11.2
Threat Intelligence
Exploit Maturity
Proof of concept
EPSS
0.05% (17th
percentile)
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-GOLANG-K8SIOINGRESSNGINXINTERNALINGRESSANNOTATIONSAUTHTLS-7707744
- published 18 Aug 2024
- disclosed 16 Aug 2024
- credit André Storfjord Kristiansen
Introduced: 16 Aug 2024
CVE-2024-7646 Open this link in a new tabHow to fix?
Upgrade k8s.io/ingress-nginx/internal/ingress/annotations/authtls
to version 1.10.4, 1.11.2 or higher.
Overview
Affected versions of this package are vulnerable to Improper Input Validation in the networking.k8s.io
or extensions
API group which allows an attacker, with permission to create Ingress objects, to bypass annotation validation.