云安全公司 Wiz 发现了 Ingress-Nginx Controller 的准入控制器组件存在严重漏洞,可能导致 Kubernetes 集群被完全接管。据估计,互联网上超过 6,000 个部署实例正面临风险。
Cloudy infosec outfit Wiz has discovered serious vulnerabilities in the admission controller component of Ingress-Nginx ...
Wiz recently published a detailed analysis of a critical vulnerability in the NGINX Ingress admission controller—what they’ve dubbed IngressNightmare (CVE-2025-1097, CVE-2025-1098, CVE-2025-1974, ...
A series of critical zero-day vulnerabilities dubbed ‘IngressNightmare’ can enable full takeover of a Kubernetes cluster — ...
能将Nginx网站平台作为Kubernetes环境输入控制器的软件系统ingress-nginx,本周发布更新版本,主要是为了修补4个漏洞,此事源于安全企业Wiz找到命名为IngressNightmare的一系列漏洞,危险程度达到重大层级,攻击者可远 ...
Five critical flaws in Ingress NGINX Controller expose 6,500+ clusters; update now to prevent unauthorized remote code ...
This week, researchers from Wiz Research released a series of vulnerabilities in the Kubernetes Ingress NGINX Controller  that, when chained together, allow an unauthorized attacker to completely ...
The vulnerabilities dubbed IngressNightmare can allow unauthenticated users to inject malicious NGINX configurations and ...
A 'nightmare', is how Wiz describes multiple critical vulnerabilities discovered in Ingress NGINX Controller for Kubernetes.
See Also: Enhance Cloud Security with AI-Driven Technologies The Kubernetes project team released patches for the Ingress ...
Critical vulnerabilities in Ingress Nginx Controller - a widely used component of the popular Kubernetes container management ...