Story perspectives
Severe 'IngressNightmare' Vulnerabilities Threaten 43% of Kubernetes Clusters
3/25/2025
50 7
1 of 2
Wiz Research Uncovers Vulnerabilities
- Wiz Research uncovered severe vulnerabilities in Ingress NGINX Controller for Kubernetes, named "IngressNightmare," enabling remote code execution.
- About 43% of 6,500 exposed clusters, including those of Fortune 500 firms, are vulnerable.
- The vulnerabilities carry a CVSS score of 9.8, requiring urgent updates to versions 1.12.1 or 1.11.5.
- Researchers advise limiting access to the admission controller and implementing strict network policies as temporary solutions.
- Vulnerabilities were reported to Kubernetes from December 2024 to January 2025, with public details released on March 10, 2025.
1 / 2
