Three unpatched high-severity security flaws have been disclosed in theΒ NGINX Ingress controllerΒ for Kubernetes that could be weaponized by a threat actor to steal secret credentials from the cluster.
The vulnerabilities are as follows -Β
CVE-2022-4886Β (CVSS score: 8.8) -Β Ingress-nginxΒ path sanitization can be bypassed to obtain the credentials of the ingress-nginx controller
CVE-2023-5043Β (