kubernetes/ingress-nginx: /metrics endpoint exposed publicly by default
Published Jan 14, 2020
5.3
MEDIUMCVSS 3.1
EPSS 1.14%
Description
Versions < 1.5 of the Kubernetes ingress default backend, which handles invalid ingress traffic, exposed prometheus metrics publicly.
Affected products
-
- Version defaultbackendStatusaffectedConstraints<1.5
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Kubernetes | K8s.gcr.io/defaultbackend | n/a |
|
- < 1.5.0
No data.
Red Hat OpenShift Container Platform 3.11
atomic-openshift
Not affected
Red Hat OpenShift Container Platform 4
openshift
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat OpenShift Container Platform 3.11 | atomic-openshift | Not affected | n/a |
| Red Hat OpenShift Container Platform 4 | openshift | Not affected | n/a |
k8s.io/ingress-nginx
Go
Introduced 0 Fixed 1.5
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| Go | k8s.io/ingress-nginx | 0 | 1.5 |
Remediation
Vendor solution
Mask the /metrics endpoint with an Ingress rule so that metrics aren't exposed publicly. See https://github.com/kubernetes/ingress-nginx/issues/1733#issuecomment-358492359
Red Hat statement
OpenShift Container Platform is not affected by this flaw as it neither uses the Kubernetes NGINX Ingress Controller nor exposes exposes metrics publicly without authentication.
References (9)
- https://access.redhat.com/security/cve/CVE-2018-1002104 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1814953 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-4671 Advisory
- https://github.com/advisories/GHSA-p3x5-5xpx-9phm Advisory
- https://github.com/kubernetes/ingress-nginx/commit/d487a50e399100ad8db12ed1d2f92271f311f676
- https://github.com/kubernetes/ingress-nginx/issues/1733
- https://github.com/kubernetes/ingress-nginx/pull/3125 x_refsource_CONFIRMPatchThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2018-1002104
- https://www.cve.org/CVERecord?id=CVE-2018-1002104
Change history (0)
No recorded changes yet.