Back

MEDIUM

kubernetes/ingress-nginx: /metrics endpoint exposed publicly by default

Published Jan 14, 2020

Description

Versions < 1.5 of the Kubernetes ingress default backend, which handles invalid ingress traffic, exposed prometheus metrics publicly.

Affected products

Remediation

Vendor solution

Mask the /metrics endpoint with an Ingress rule so that metrics aren't exposed publicly. See https://github.com/kubernetes/ingress-nginx/issues/1733#issuecomment-358492359

Red Hat statement

OpenShift Container Platform is not affected by this flaw as it neither uses the Kubernetes NGINX Ingress Controller nor exposes exposes metrics publicly without authentication.

References (9)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner kubernetes
Published Jan 14, 2020
Updated Sep 16, 2024
Reserved Dec 5, 2018
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Low
Public date Jan 15, 2020
ENISA EUVD
Assigner kubernetes
Published Jan 14, 2020
Updated Sep 16, 2024
Exploited since n/a
EUVD-2022-4671 GHSA-P3X5-5XPX-9PHM