Vulnerability record · CVE-2023-5044 · published 25 October 2023
CVE-2023-5044: ingress-nginx permanent-redirect annotation code injection
Kubernetes · Ingress Nginx
CVE-2023-5044 is a code injection flaw in ingress-nginx reached through the nginx.ingress.kubernetes.io/permanent-redirect annotation, caused by improper input validation (CWE-20, CWE-94). An actor able to set that annotation can inject code into the generated nginx configuration, which matters because ingress-nginx sits in the request path for cluster traffic.
Description
Code injection via nginx.ingress.kubernetes.io/permanent-redirect annotation.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityCVSS 8.8 with high EPSS (99th percentile) and network reachability, though exploitation requires the low-level privilege of modifying Ingress annotations and no KEV listing exists.
What it is
CVE-2023-5044 is a code injection flaw in ingress-nginx reached through the nginx.ingress.kubernetes.io/permanent-redirect annotation, caused by improper input validation (CWE-20, CWE-94). An actor able to set that annotation can inject code into the generated nginx configuration, which matters because ingress-nginx sits in the request path for cluster traffic.
Impact
Successful exploitation gives code execution in the ingress-nginx context with high confidentiality, integrity and availability impact per the CVSS vector. The attacker gains control over the ingress controller's behavior rather than only a redirect.
Attack surface
Reached over the network (AV:N) with low attack complexity and no user interaction; the vector requires low privileges (PR:L), consistent with an actor who can create or modify Ingress resources and their annotations. No authentication bypass is implied beyond those privileges.
Exploitation
Not listed in CISA KEV and no ransomware association is recorded, but EPSS is 0.56605 (99th percentile), indicating elevated predicted exploitation activity; references are vendor advisories and mitigation guidance rather than public exploit code.
What to do
- Upgrade ingress-nginx to a version that fixes the annotation handling, following the vendor advisory and Kubernetes security announcement.
- Restrict who can create or modify Ingress objects and annotations via RBAC, limiting write access to trusted operators.
- Admission-control or policy checks that reject or sanitize the nginx.ingress.kubernetes.io/permanent-redirect annotation from untrusted sources.
- Audit existing Ingress resources for unexpected or attacker-controlled permanent-redirect annotation values and remove them.
Detection
- Monitor Kubernetes audit logs for create/update/patch events on Ingress resources that set or change the permanent-redirect annotation.
- Alert on RBAC changes granting Ingress write permissions to new or unexpected subjects.
- Review generated nginx configuration in ingress-nginx pods for unexpected directives or injected content.
- Watch ingress-nginx logs and process behavior for anomalies following annotation changes.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://www.openwall.com/lists/oss-security/2023/10/25/3 | Mailing ListThird Party Advisory |
| https://github.com/kubernetes/ingress-nginx/issues/10572 | Issue TrackingMitigationVendor Advisory |
| https://groups.google.com/g/kubernetes-security-announce/c/ukuYYvRNel0 | Mailing ListMitigation |
| https://security.netapp.com/advisory/ntap-20240307-0012/ | |
| http://www.openwall.com/lists/oss-security/2023/10/25/3 | Mailing ListThird Party Advisory |
| https://github.com/kubernetes/ingress-nginx/issues/10572 | Issue TrackingMitigationVendor Advisory |
| https://groups.google.com/g/kubernetes-security-announce/c/ukuYYvRNel0 | Mailing ListMitigation |
| https://security.netapp.com/advisory/ntap-20240307-0012/ |
Track CVE-2023-5044 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2023-5044), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.