A security issue was discovered in Kubernetes where under certain conditions, an unauthenticated attacker with access to the pod network can achieve arbitrary code execution in the context of the ingress-nginx controller. This can lead to disclosure of Secrets accessible to the controller. (Note that in the default installation, the controller can access all Secrets cluster-wide.)
Advisories
Source ID Title
Github GHSA Github GHSA GHSA-mgvx-rpfc-9mpv ingress-nginx admission controller RCE escalation
Fixes

Solution

No solution given by the vendor.


Workaround

Before applying the patch, this issue can be mitigated by disabling the Validating Admission Controller functionality of ingress-nginx.

History

Wed, 16 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.87048}

epss

{'score': 0.87073}


Wed, 28 May 2025 17:15:00 +0000

Type Values Removed Values Added
References

Thu, 22 May 2025 03:00:00 +0000


Wed, 26 Mar 2025 02:15:00 +0000


Tue, 25 Mar 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 24 Mar 2025 23:45:00 +0000

Type Values Removed Values Added
Description A security issue was discovered in Kubernetes where under certain conditions, an unauthenticated attacker with access to the pod network can achieve arbitrary code execution in the context of the ingress-nginx controller. This can lead to disclosure of Secrets accessible to the controller. (Note that in the default installation, the controller can access all Secrets cluster-wide.)
Title ingress-nginx admission controller RCE escalation
Weaknesses CWE-653
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: kubernetes

Published:

Updated: 2025-03-27T03:55:19.309Z

Reserved: 2025-03-04T21:34:07.543Z

Link: CVE-2025-1974

cve-icon Vulnrichment

Updated: 2025-03-25T13:40:25.261Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-03-25T00:15:14.753

Modified: 2025-03-27T16:45:46.410

Link: CVE-2025-1974

cve-icon Redhat

Severity :

Publid Date: 2025-03-24T23:28:48Z

Links: CVE-2025-1974 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2025-07-21T15:17:49Z