CVE-2025-1974

A security issue was discovered in Kubernetes where under certain conditions, an unauthenticated attacker with access to the pod network can achieve arbitrary code execution in the context of the ingress-nginx controller. This can lead to disclosure of Secrets accessible to the controller. (Note that in the default installation, the controller can access all Secrets cluster-wide.)
Configurations

No configuration.

History

10 Nov 2025, 18:16

Type Values Removed Values Added
References
  • () https://github.com/B1ack4sh/Blackash-CVE-2025-1974 -

03 Nov 2025, 21:18

Type Values Removed Values Added
References
  • () https://security.netapp.com/advisory/ntap-20250328-0008/ -

Information

Published : 2025-03-25 00:15

Updated : 2025-11-10 18:16


NVD link : CVE-2025-1974

Mitre link : CVE-2025-1974

CVE.ORG link : CVE-2025-1974


JSON object : View

Products Affected

No product.

CWE
CWE-653

Improper Isolation or Compartmentalization