Skip to content
Appaloosa Scout
Language selector
fr en

Vulnerability · NVD

CVE-2025-1974

CVE-2025-1974 : critical severity (CVSS 9.8). No tracked catalog app is linked to this CVE.

Severity (CVSS)
9.8

NVD scale

Exploitation
99.5 %

EPSS, predicted over 30 days

Tracked apps
0
Still exposed
0

A security issue was discovered in Kubernetes where under certain conditions, an unauthenticated attacker with access to the pod network can achieve arbitrary code execution in the context of the ingress-nginx controller. This can lead to disclosure of Secrets accessible to the controller. (Note that in the default installation, the controller can access all Secrets cluster-wide.)

Attack vector : Network No privileges required No user interaction
Show raw CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS 99.52% exploit likely percentile 99.9%
View on NVD ↗