Versions < 1.5 of the Kubernetes ingress default backend, which handles invalid ingress traffic, exposed prometheus metrics publicly.
Workaround:
The product inserts sensitive information into debugging code, which could expose this information if the debugging code is not disabled in production.
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
Link | Tags |
---|---|
https://github.com/kubernetes/ingress-nginx/pull/3125 | third party advisory patch |