9.8 CVE-2025-1974

Exploit
 

A security issue was discovered in Kubernetes where under certain conditions, an unauthenticated attacker with access to the pod network can achieve arbitrary code execution in the context of the ingress-nginx controller. This can lead to disclosure of Secrets accessible to the controller. (Note that in the default installation, the controller can access all Secrets cluster-wide.)
https://nvd.nist.gov/vuln/detail/CVE-2025-1974

Categories

CWE-653 : Improper Isolation or Compartmentalization
When a weakness occurs in functionality that is accessible by lower-privileged users, then without strong boundaries, an attack might extend the scope of the damage to higher-privileged users.

References


 

CPE

cpe start end


REMEDIATION




EXPLOITS


Exploit-db.com

id description date
No known exploits

POC Github

Url
https://github.com/dttuss/IngressNightmare-RCE-POC
https://github.com/m-q-t/ingressnightmare-detection-poc
https://github.com/hi-unc1e/CVE-2025-1974-poc
https://github.com/rjhaikal/POC-IngressNightmare-CVE-2025-1974
https://github.com/zulloper/CVE-2025-1974

Other Nist (github, ...)

Url
No known exploits


CAPEC


Common Attack Pattern Enumerations and Classifications

id description severity
No entry