Critical Ingress NGINX Controller vulnerabilities disclosed in Kubernetes
On March 24, 2025, four critical Ingress NGINX Controller vulnerabilities were publicly disclosed. These flaws enable unauthenticated remote code execution (RCE), unrestricted access to secrets across all namespaces, and the possibility of full Kubernetes cluster takeover. Each vulnerability resides in the controller’s admission component, a service commonly exposed to the internet without authentication controls. Ingress …
Critical Ingress NGINX Controller vulnerabilities disclosed in Kubernetes Read More »