• XSS.stack #1 – первый литературный журнал от юзеров форума

Remote Ingress NGINX Controller RCE exploit chain (CVE-2025-24513, CVE-2025-24514, CVE-2025-1097, CVE-2025-1098, CVE-2025-1974)

no1

Floppa
Пользователь
Регистрация
19.08.2019
Сообщения
93
Реакции
81
Гарант сделки
1
A new chain of vulnerabilities calles IngressNightmare is trending.

Found this poc :
https://github.com/sandumjacob/IngressNightmare-POCs/tree/main/CVE-2025-1974

but it does not includes the full chain and according to the author, has been written before the publication so should be not perfect.
Please share here if someone publish further researches on this, I think it needs a manifest with vulnerable annotation to be added for it to work but I'll be able to further test in local env tonight.
 


Напишите ответ...
  • Вставить:
Прикрепить файлы
Верх