# \[Ingress-nginx Security Advisory\] CVE-2024-7646: Ingress-nginx Annotation Validation Bypass

**URL:** <https://discuss.kubernetes.io/t/ingress-nginx-security-advisory-cve-2024-7646-ingress-nginx-annotation-validation-bypass/29415>\
**Category:** Announcements\
**Created:** [August 16, 2024, 5:09pm UTC](https://discuss.kubernetes.io/t/ingress-nginx-security-advisory-cve-2024-7646-ingress-nginx-annotation-validation-bypass/29415 "2024-08-16T17:09:59Z")\
**Posts on this page:** 1\
**Page:** 1

<div class="post-metadata">

**Author:** ![Security\_k8s.io](https://avatars.discourse-cdn.com/v4/letter/s/da6949/32.png) [@Security\_k8s.io](https://discuss.kubernetes.io/u/Security_k8s.io)\
**Post date:** [August 16, 2024, 5:09pm UTC](https://discuss.kubernetes.io/t/ingress-nginx-security-advisory-cve-2024-7646-ingress-nginx-annotation-validation-bypass/29415/1 "2024-08-16T17:09:59Z")

</div>

Hello Kubernetes Community,

A security issue was discovered in ingress-nginx where an actor with permission to create Ingress objects (in the `networking.k8s.io` or `extensions` API group) can bypass annotation validation to inject arbitrary commands and obtain the credentials of the ingress-nginx controller. In the default configuration, that credential has access to all secrets in the cluster.

This issue has been rated High (8.8) [CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H](https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H) and assigned CVE-2024-7646.

Am I vulnerable?

This bug affects ingress-nginx. If you do not have ingress-nginx installed on your cluster, you are not affected. You can check this by running `kubectl get po -A` and looking for `ingress-nginx-controller`.

Multi-tenant environments where non-admin users have permissions to create Ingress objects are most affected by this issue.

Affected Versions

ingress-nginx controller \< v1.11.2

How do I mitigate this vulnerability?

This issue can be mitigated by upgrading to the fixed version.

Fixed Versions

ingress-nginx controller v1.11.2

Detection

Review your Kubernetes audit logs for Ingress objects created with annotations (e.g. `nginx.ingress.kubernetes.io/auth-tls-verify-client`) that contain carriage returns (`\r`).

If you find evidence that this vulnerability has been exploited, please contact [security@kubernetes.io](mailto:security@kubernetes.io)

Additional Details

See the GitHub issue for more details:

[https://github.com/kubernetes/kubernetes/issues/126744](https://github.com/kubernetes/kubernetes/issues/126744)

Acknowledgements

This vulnerability was reported by André Storfjord Kristiansen @dev-bio.

The issue was fixed and coordinated by the fix team:

André Storfjord Kristiansen @dev-bio

Jintao Zhang @tao12345666333

Marco Ebert @Gacko

Thank You,

Craig Ingram on behalf of the Kubernetes Security Response Committee
