| id: GO-2024-2428 |
| modules: |
| - module: k8s.io/ingress-nginx |
| non_go_versions: |
| - fixed: 1.9.0 |
| vulnerable_at: 1.0.0-alpha.1 |
| summary: |- |
| Ingress-nginx code injection via nginx.ingress.kubernetes.io/permanent-redirect |
| annotation in k8s.io/ingress-nginx |
| cves: |
| - CVE-2023-5044 |
| ghsas: |
| - GHSA-fp9f-44c2-cw27 |
| references: |
| - advisory: https://github.com/advisories/GHSA-fp9f-44c2-cw27 |
| - advisory: https://nvd.nist.gov/vuln/detail/CVE-2023-5044 |
| - web: http://www.openwall.com/lists/oss-security/2023/10/25/3 |
| - web: https://github.com/kubernetes/ingress-nginx/issues/10572 |
| - web: https://groups.google.com/g/kubernetes-security-announce/c/ukuYYvRNel0 |
| - web: https://security.netapp.com/advisory/ntap-20240307-0012 |
| source: |
| id: GHSA-fp9f-44c2-cw27 |
| created: 2024-08-16T15:55:16.958982-04:00 |
| review_status: UNREVIEWED |
| unexcluded: EFFECTIVELY_PRIVATE |