Skip to content

Comment on Critical Unauthenticated Remote Code Execution Vulnerabilities in Ingress NGINXparent

Comments

I think you've got it. But I'm on the fence about the rest. I mean, you're spot on that it would require a monumentally bad collection of misconfigurations to mount the attack and 9.8 seems to be somewhat histrionic. But considering how often I run into a monumentally bad collection of misconfigurations when doing incident post-mortems, I'm sorely tempted to be ok with assigning ratings with the assumption that the target has done all the compensating controls wrong. YMMV.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.