Home / Companies / Detectify / Blog / Post Details
Content Deep Dive

Security Update: Publicly Exposed Ingress NGINX Admission

Blog post from Detectify

Post Details
Company
Date Published
Author
Detectify
Word Count
521
Company Posts That Month
3
Language
-
Hacker News Points
-
Post removed?
No
Summary

A series of vulnerabilities, collectively termed IngressNightmare, have been identified in the ingress-nginx, a popular Kubernetes ingress controller, which can be exploited to inject configurations via the Validating Admission Controller, potentially allowing unauthorized access to sensitive data and complete cluster takeover. These vulnerabilities (CVE-2025-1097, CVE-2025-1098, CVE-2025-24514, CVE-2025-1974) affect all versions of ingress-nginx but are remedied in versions 1.12.1 and 1.11.5. Detectify has released a vulnerability assessment tool to identify exposed Ingress NGINX admission controllers by analyzing TLS certificates, offering a reliable detection method due to the unique characteristics of Kubernetes' self-signed certificates. As mitigation, users are advised to upgrade to the latest patched versions or temporarily disable the Validating Admission Controller if immediate patching is not possible. The article also highlights that Detectify continues to provide updates in their product log and offers support and trial options for users seeking to enhance their security posture.

Trends Found in this Post
Trend Post Mentions Total Month Mentions Posts Companies MoM
Kubernetes 6 1,484 191 81 +77%
Secrets Management 2 1,233 139 73 +105%
Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.