Vulnerability Details CVE-2018-1002104
Versions < 1.5 of the Kubernetes ingress default backend, which handles invalid ingress traffic, exposed prometheus metrics publicly.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.004
EPSS Ranking 61.8%
CVSS Severity
CVSS v3 Score 5.3
CVSS v2 Score 5.0
Products affected by CVE-2018-1002104
-
cpe:2.3:a:kubernetes:nginx_ingress_controller:0.10.0
-
cpe:2.3:a:kubernetes:nginx_ingress_controller:0.10.1
-
cpe:2.3:a:kubernetes:nginx_ingress_controller:0.10.2
-
cpe:2.3:a:kubernetes:nginx_ingress_controller:0.11.0
-
cpe:2.3:a:kubernetes:nginx_ingress_controller:0.12.0
-
cpe:2.3:a:kubernetes:nginx_ingress_controller:0.13.0
-
cpe:2.3:a:kubernetes:nginx_ingress_controller:0.14.0
-
cpe:2.3:a:kubernetes:nginx_ingress_controller:0.15.0
-
cpe:2.3:a:kubernetes:nginx_ingress_controller:0.16.0
-
cpe:2.3:a:kubernetes:nginx_ingress_controller:0.16.1
-
cpe:2.3:a:kubernetes:nginx_ingress_controller:0.16.2
-
cpe:2.3:a:kubernetes:nginx_ingress_controller:0.17.0
-
cpe:2.3:a:kubernetes:nginx_ingress_controller:0.17.1
-
cpe:2.3:a:kubernetes:nginx_ingress_controller:0.18.0
-
cpe:2.3:a:kubernetes:nginx_ingress_controller:0.19.0
-
cpe:2.3:a:kubernetes:nginx_ingress_controller:0.20.0
-
cpe:2.3:a:kubernetes:nginx_ingress_controller:0.21.0
-
cpe:2.3:a:kubernetes:nginx_ingress_controller:0.22.0
-
cpe:2.3:a:kubernetes:nginx_ingress_controller:0.9.0
-
cpe:2.3:a:kubernetes:nginx_ingress_controller:0.9.1
-
cpe:2.3:a:kubernetes:nginx_ingress_controller:0.9.2
-
cpe:2.3:a:kubernetes:nginx_ingress_controller:0.9.3
-
cpe:2.3:a:kubernetes:nginx_ingress_controller:0.9.4
-
cpe:2.3:a:kubernetes:nginx_ingress_controller:0.9.5
-
cpe:2.3:a:kubernetes:nginx_ingress_controller:0.9.6