Junglewise Threat Intelligence

CVE-2021-25748: Ingress-nginx `path` sanitization can be bypassed with newline character

CVE-2021-25748 · Severity: low · CVSS 3.1 · Published 2023-05-24

Technologies: k8s.io/ingress-nginx (Go). Vendors: Go.

Executive brief

Ingress-nginx `path` sanitization can be bypassed with newline character

Affected products

  • Go k8s.io/ingress-nginx

Related threats