cross-posted from: https://lemmy.world/post/27407351

When combined with today’s other vulnerabilities, CVE-2025-1974 means that anything on the Pod network has a good chance of taking over your Kubernetes cluster, with no credentials or administrative access required.

  • irotsoma
    link
    fedilink
    English
    arrow-up
    3
    ·
    17 天前

    Yes it’s defects in the ingress-nginx controller package.