In versions 2.x before 2.3.0 and all versions of 1.x, An attacker authorized to create or update ingress objects can obtain the secrets available to the NGINX Ingress Controller. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
| Software | From | Fixed in |
|---|---|---|
| f5 / nginx_ingress_controller | 1.0.0 | 2.3.0 |