CVE-2022-30535
04.08.2022, 18:15
In versions 2.x before 2.3.0 and all versions of 1.x, An attacker authorized to create or update ingress objects can obtain the secrets available to the NGINX Ingress Controller. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.Enginsight
Vendor | Product | Version |
---|---|---|
f5 | nginx_ingress_controller | 1.0.0 ≤ 𝑥 < 2.3.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration