CVE-2025-1974

CVSS 3.1 Score 9.8 of 10 (high)

Details

Published Mar 25, 2025
Updated: Mar 27, 2025
CWE ID 653

Summary

CVE-2025-1974 is a critical vulnerability affecting Kubernetes. Under specific conditions, an unauthenticated attacker can infiltrate the pod network and execute arbitrary code in the context of the ingress-nginx controller. This assault could potentially result in the exposure of sensitive Secrets, which the controller has access to in a standard setup, across the entire cluster.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Kubernetes Ingress-nginx

Affected Vendors

  • Kubernetes