Vulnerability CVE-2022-4886


Published: 2023-10-25

Description:
Ingress-nginx `path` sanitization can be bypassed with `log_format` directive.

 References:
https://github.com/kubernetes/ingress-nginx/issues/10570
https://groups.google.com/g/kubernetes-security-announce/c/ge7u3qCwZLI
http://www.openwall.com/lists/oss-security/2023/10/25/5

Copyright 2026, cxsecurity.com

 

Back to Top