Description

A security issue was discovered in ingress-nginx https://github.com/kubernetes/ingress-nginx where attacker-provided data are included in a filename by the ingress-nginx Admission Controller feature, resulting in directory traversal within the container. This could result in denial of service, or when combined with other vulnerabilities, limited disclosure of Secret objects from the cluster.

INFO

Published Date :

2025-03-24T23:29:25.215Z

Last Modified :

2025-11-03T21:12:43.390Z

Source :

kubernetes
AFFECTED PRODUCTS

The following products are affected by CVE-2025-24513 vulnerability.

Vendors Products
Kubernetes
  • Ingress-nginx
REFERENCES

Here, you will find a curated list of external links that provide in-depth information to CVE-2025-24513.

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact