Critical Unauthenticated Remote Code Execution Vulnerabilities in Ingress NGINX
wiz.io
wiz.io
I don't understand that. Under what circumstances are those admission controllers exposed to the public internet? The k8s API of my EKS is definitely exposed to the public internet, but my understanding is that it will say "no" to whatever unauthenticated request it receives, isn't it?
Nginx isn't the problem, but I don't think you can really get away from including it in the title given the name of the component
Do I understand this correctly?
- To exploit this vulnerability, you need to send a request directly to a kubernetes resource, the admission controller, something that is generally not possible unless you have a misconfiguration on the level of "MySQL server is reachable from any external ip".
- Exploiting this vulnerability by communicating with the nginx server itself is not possible.
- Normally, kubernetes resources should never be accessible from the internet. This requires an obviously dangerous misconfiguration or extremely lax security standards. Ideally, no one should be able to tell you are using kubernetes from outside.
I built clusters using ingress-nginx at my old job and I can guarantee you that not one single endpoint of k8s was accessible outside of NAT.
Yes, if the call is coming from inside the house, you're already in a bad spot, but going beyond capabilities like DDoS and network traversal (such as also gaining the ability to enumerate the secrets in your k8s) is quite a bit worse.
Also, a public-facing running in the cluster itself could have a vulnerability that, combined with this bug, gives an attacker much further reach.
The Traefik one is also quite pleasant. It does surprise me a bit that we don’t see more ingress controllers built on regular web servers, like a Caddy or Apache2 one, especially because a configurable version of the latter would also help with some homelab or long lived/legacy project environments, given how widespread that web server is.
> Our research show that over 41% of internet-facing clusters are running Ingress-NGINX.
This definitely feels like one of those cases where more fragmentation is a good thing, because at least it limits the fallout of issues like this. I can bet that many out there won’t get the memo and will keep running insecure software.