Security Risk Advisors
IngressNightmare Vulnerabilities in Ingress NGINX Controller
Pages
3
Time to read
3 mins
Publication
Language
English
Pages
3
Time to read
3 mins
Publication
Language
English
This technical report discusses the critical remote code execution vulnerabilities identified in the Ingress NGINX Controller for Kubernetes, collectively referred to as 'IngressNightmare.' Discovered by Wiz Research, these vulnerabilities allow unauthenticated attackers to execute arbitrary code on the Ingress NGINX Controller's pod by exploiting the admission controller component. The report details how attackers can send specially crafted AdmissionReview requests to the unauthenticated endpoint, leading to a potential takeover of Kubernetes clusters. The vulnerabilities are particularly concerning due to the elevated privileges of the Ingress NGINX Controller pod, which can grant access to sensitive credentials across all namespaces. The report also outlines the impact of these vulnerabilities, including the risk of deploying malicious workloads and disrupting services. Recommendations for organizations include identifying affected clusters, updating to patched versions, and implementing strict network access policies to mitigate risks associated with these vulnerabilities.