CVE-2021-25742

Related Vulnerabilities: CVE-2021-25742  

No description is available for this CVE.

Description

No description is available for this CVE.

Statement

OpenShift Container Platform does not use NGINX for Ingress and is therefore not affected by this vulnerability.

OpenShift Container Platform does not use NGINX for Ingress and is therefore not affected by this vulnerability.

Additional Information

  • Bugzilla 2012036: CVE-2021-25742 k8s.io/ingress-nginx: Custom snippets allows retrieval of ingress-nginx serviceaccount token and secrets across all namespaces
  • CWE-522: Insufficiently Protected Credentials
  • FAQ: Frequently asked questions about CVE-2021-25742