CVE-2025-1974
Description
A flaw was found in Kubernetes where, under certain conditions, an unauthenticated attacker with access to the pod network can achieve arbitrary code execution in the context of the ingress-nginx controller. This issue can lead to the disclosure of Secrets accessible to the controller. Note that the controller can access all Secrets cluster-wide in the default installation.
Statement
Red Hat Product Security has determined that this vulnerability does not affect any currently supported Red Hat product.
Ingress-NGINX is not the default ingress controller shipped with Red Hat OpenShift. Instead, Red Hat OpenShift ships with and supports its own ingress controller based on HAProxy, known as the OpenShift Router. This controller is fully integrated with OpenShift's networking and security models and is managed by the Ingress Operator.
Understanding the Weakness (CWE)
Access Control
Technical Impact: Gain Privileges or Assume Identity; Bypass Protection Mechanism
The exploitation of a weakness in low-privileged areas of the software can be leveraged to reach higher-privileged areas without having to overcome any additional obstacles.
Frequently Asked Questions
Not sure what something means? Check out our Security Glossary.
Want to get errata notifications? Sign up here.