← العودة للجدول
CVE-2025-1097
IngressNightmare Vulnerabilities: All You Need to Know
📅 2025-03-26 13:15:57
🔴 Critical 🔥 No Aqua Security Exploit Containers

📋 الوصف الكامل

On March 24, 2025, a series of several critical vulnerabilities (CVE-2025-1097, CVE-2025-1098, CVE-2025-24514, and CVE-2025-1974) were disclosed in the ingress-nginx Controller for Kubernetes, collectively termed IngressNightmare. These vulnerabilities could lead to a complete cluster takeover by allowing attackers unauthorized access to all secrets stored across all namespaces

💻 الأنظمة المتأثرة

Kubernetes 1.30.x

⚠️ نوع التهديد

Exploit

🔗 CVE ID

CVE-2025-1097

📡 المصدر

Aqua Security

✅ الحلول والتخفيف

Refer to CVE-2025-1097 NVD advisory

🔗 المصدر الأصلي ← 📘 NVD ← ⚡ CISA KEV ←