Description
A security issue was discovered in ingress-nginx https://github.com/kubernetes/ingress-nginx where attacker-provided data are included in a filename by the ingress-nginx Admission Controller feature, resulting in directory traversal within the container. This could result in denial of service, or when combined with other vulnerabilities, limited disclosure of Secret objects from the cluster.
INFO
Published Date :
2025-03-24T23:29:25.215Z
Last Modified :
2025-11-03T21:12:43.390Z
Source :
kubernetes
AFFECTED PRODUCTS
The following products are affected by CVE-2025-24513 vulnerability.
| Vendors | Products |
|---|---|
| Kubernetes |
|
REFERENCES
Here, you will find a curated list of external links that provide in-depth information to CVE-2025-24513.
CVSS Vulnerability Scoring System
Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact