Ingress-nginx `path` sanitization can be bypassed with `log_format` directive.
2023-10-25T20:15:09.790
2025-02-13T17:15:51.100
Modified
CVSSv3.1: 8.8 (HIGH)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | kubernetes | ingress-nginx | < 1.8.0 | Yes |