A security issue was discovered in ingress-nginx where a user that can create or update ingress objects can use the custom snippets feature to obtain all secrets in the cluster.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Ingress-nginx | Kubernetes | * | 0.49.1 (excluding) |
Ingress-nginx | Kubernetes | 1.0.0 (including) | 1.0.0 (including) |