Executive brief
ngress-nginx controller - configuration injection via unsanitized auth-tls-match-cn annotation in k8s.io/ingress-nginx
Affected products
- Go k8s.io/ingress-nginx
Junglewise Threat Intelligence
CVE-2025-1097 · Severity: low · CVSS 3.1 · Published 2025-03-25
Technologies: k8s.io/ingress-nginx (Go). Vendors: Go.
ngress-nginx controller - configuration injection via unsanitized auth-tls-match-cn annotation in k8s.io/ingress-nginx