Hacker News new | ask | show | jobs
Three new Nginx ingress controller vulnerabilities and the affect on Kubernetes (armosec.io)
5 points by jkaftzan 969 days ago
1 comments

CVE-2023-5043, CVE-2023-5044 and CVE-2022-4886 can be exploited by attacker to steal secret credentials from K8s cluster. Three security issues were reported on October 27th by the Kubernetes security community, all of them related to the popular NGINX ingress component.