HAProxy Kubernetes Ingress Controller before 3.1.13, when the config-snippets feature flag is used, accepts config snippets from users with create/update permissions. This can result in obtaining an ingress token secret as a response. The fixed versions of HAProxy Enterprise Kubernetes Ingress Controller are 3.0.16-ee1, 1.11.13-ee1, and 1.9.15-ee1.
Metrics
Affected Vendors & Products
References
History
Wed, 08 Oct 2025 17:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Wed, 08 Oct 2025 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | HAProxy Kubernetes Ingress Controller before 3.1.13, when the config-snippets feature flag is used, accepts config snippets from users with create/update permissions. This can result in obtaining an ingress token secret as a response. The fixed versions of HAProxy Enterprise Kubernetes Ingress Controller are 3.0.16-ee1, 1.11.13-ee1, and 1.9.15-ee1. | |
Weaknesses | CWE-791 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-10-08T17:10:15.387Z
Reserved: 2025-09-12T00:00:00.000Z
Link: CVE-2025-59303

Updated: 2025-10-08T17:10:08.106Z

Status : Received
Published: 2025-10-08T16:15:38.870
Modified: 2025-10-08T16:15:38.870
Link: CVE-2025-59303

No data.

No data.