{"id":"CVE-2023-5043","aliases":["GHSA-5wj4-wffq-3378"],"title":"Ingress nginx annotation injection causes arbitrary command execution","summary":"Ingress nginx annotation injection causes arbitrary command execution","severity":"high","cvss":7.6,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L","vendor":"ingress-nginx","product":"k8s.io/ingress-nginx","ecosystem":"go","affected":["k8s.io/ingress-nginx < 1.9.0"],"patched":["k8s.io/ingress-nginx 1.9.0"],"published":"2023-10-25","updated":"2026-08-07","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/GHSA-5wj4-wffq-3378","references":[{"url":"https://nvd.nist.gov/vuln/detail/CVE-2023-5043"},{"url":"https://github.com/kubernetes/ingress-nginx/issues/10571"},{"url":"https://groups.google.com/g/kubernetes-security-announce/c/pVsXsOpxYZo"},{"url":"https://security.netapp.com/advisory/ntap-20240307-0012"},{"url":"http://www.openwall.com/lists/oss-security/2023/10/25/4"}],"tags":["osv","go","exploit-available"],"epss":0.02234,"epssPercentile":0.81832,"ingestedAt":"2026-08-07T19:14:15.880Z","exploits":{"github":1,"githubRepos":["https://github.com/r0binak/CVE-2023-5043"],"checkedAt":"2026-09-21T15:26:00.837Z"},"exploitAvailable":true,"slug":"CVE-2023-5043","body":"## Overview\n\n### Issue Details\nA security issue was identified in ingress-nginx where the nginx.ingress.kubernetes.io/configuration-snippet annotation on an Ingress object (in the networking.k8s.io or extensions API group) can be used to inject arbitrary commands, and obtain the credentials of the ingress-nginx controller. In the default configuration, that credential has access to all secrets in the cluster.\n\nThis issue has been rated High (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L), and assigned CVE-2023-5043.\n\n### Affected Components and Configurations\nThis bug affects ingress-nginx. If you do not have ingress-nginx installed on your cluster, you are not affected. You can check this by running kubectl get po -n ingress-nginx.\n\nIf you are running the “chrooted” ingress-nginx controller introduced in v1.2.0 (gcr.io/k8s-staging-ingress-nginx/controller-chroot), command execution is possible but credential extraction is not, so the High severity does not apply.\n\nMulti-tenant environments where non-admin users have permissions to create Ingress objects are most affected by this issue.\n\n#### Affected Versions\n<v1.9.0\n#### Versions allowing mitigation\nv1.9.0\n### Mitigation\nIngress Administrators should set the --enable-annotation-validation flag to enforce restrictions on the contents of ingress-nginx annotation fields.\n\n### Detection\nIf you find evidence that this vulnerability has been exploited, please contact security@kubernetes.io\n\n### Additional Details\nSee ingress-nginx Issue [#10571](https://github.com/kubernetes/ingress-nginx/issues/10571) for more details.\n\n### Acknowledgements\nThis vulnerability was reported by suanve\n\nThank You,\nCJ Cullen on behalf of the Kubernetes Security Response Committee\n\n## Affected packages\n\n- `k8s.io/ingress-nginx < 1.9.0`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `k8s.io/ingress-nginx 1.9.0`","depth":"midnight","depthScore":54,"depthScoreParts":{"impact":41.8,"likelihood":0.4,"exploitation":12,"ransomware":0},"changes":[{"seq":4670,"id":"CVE-2023-5043","ts":1788887197999,"field":"exploit_available","old":"false","new":"true"},{"seq":3553,"id":"CVE-2023-5043","ts":1788886314163,"field":"exploit_available","old":"true","new":"false"},{"seq":2407,"id":"CVE-2023-5043","ts":1788882983388,"field":"exploit_available","old":"false","new":"true"},{"seq":1436,"id":"CVE-2023-5043","ts":1788882396339,"field":"exploit_available","old":"true","new":"false"},{"seq":550,"id":"CVE-2023-5043","ts":1788881832676,"field":"exploit_available","old":"false","new":"true"}]}