This repository was archived by the owner on Mar 24, 2026. It is now read-only.
-
Notifications
You must be signed in to change notification settings - Fork 8.5k
Moderate severity CVE-2025-23419 flagged #14181
Copy link
Copy link
Closed
Labels
kind/bugCategorizes issue or PR as related to a bug.Categorizes issue or PR as related to a bug.needs-priorityneeds-triageIndicates an issue or PR lacks a `triage/foo` label and requires one.Indicates an issue or PR lacks a `triage/foo` label and requires one.
Description
Version
ingress-nginx v1.14.0, .....
Scanner
https://nvd.nist.gov/vuln/detail/CVE-2025-23419
GHSA-84xh-pwc6-7g4g
Test With
Version scanned: ingress-nginx v1.14.0 (latest)
Description
When multiple server blocks are configured to share the same IP address and port, an attacker can use session resumption to bypass client certificate authentication requirements on these servers. This vulnerability arises when TLS Session Tickets
Remediation:
Apply the latest patches and updates provided by the respective vendors.
Bump NGINX version to 1.27.4 (current 1.27.1)
Reactions are currently unavailable
Metadata
Metadata
Labels
kind/bugCategorizes issue or PR as related to a bug.Categorizes issue or PR as related to a bug.needs-priorityneeds-triageIndicates an issue or PR lacks a `triage/foo` label and requires one.Indicates an issue or PR lacks a `triage/foo` label and requires one.
Type
Projects
Status
Done