CVE-2025-1974
CVSS 3.1 Score 9.8 of 10 (high)
Details
Published Mar 25, 2025
Updated: Mar 27, 2025
CWE ID 653
Summary
CVE-2025-1974 is a critical vulnerability affecting Kubernetes. Under specific conditions, an unauthenticated attacker can infiltrate the pod network and execute arbitrary code in the context of the ingress-nginx controller. This assault could potentially result in the exposure of sensitive Secrets, which the controller has access to in a standard setup, across the entire cluster.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Kubernetes Ingress-nginx
Affected Vendors
- Kubernetes