Share
## https://sploitus.com/exploit?id=1E96D868-3C24-5D4E-9BCE-9B2D80870880
# CVE-2025-1974
> ํ™”์ดํŠธํ–‡ ์Šค์ฟจ 3๊ธฐ - [๊น€์†Œ์€ (@salt318)] (https://github.com/salt318/vulhub)

### ์š”์•ฝ

- ์ฟ ๋ฒ„๋„คํ‹ฐ์Šค์˜ ํ•ต์‹ฌ ๋ณด์•ˆ ๋ฉ”์ปค๋‹ˆ์ฆ˜์ธ Ingress-NGINX Admission Controller์˜ ๊ฒฐํ•จ์œผ๋กœ ์ธํ•ด ๋ฐœ์ƒ
- Ingress-NGINX Admission Controller๋Š” ์ธ์ฆ ์—†์ด ๋„คํŠธ์›Œํฌ์— ๋…ธ์ถœ๋จ
- ์ด๋กœ ์ธํ•ด ๊ณต๊ฒฉ์ž๊ฐ€ ์•…์„ฑ AdmissionReview ์š”์ฒญ์„ ์กฐ์ž‘ํ•˜์—ฌ Ingress ๋ฆฌ์†Œ์Šค์— ๋ฌด๋‹จ ๊ตฌ์„ฑ์„ ์‚ฝ์ž…ํ•  ์ˆ˜ ์žˆ์Œ
- ๋‹ค๋ฅธ ์ทจ์•ฝ์ ๊ณผ ์—ฐ๊ณ„๋  ๊ฒจ์—ฌ์šฐ ์›๊ฒฉ ์ฝ”๋“œ ์‹คํ–‰ ๊ฐ€๋Šฅ (CVE-2025-24514, CVE-2025-1097 ๋˜๋Š” CVE-2025-1098)


### ํ™˜๊ฒฝ ๊ตฌ์„ฑ ๋ฐ ์‹คํ–‰
- `docker compose up -d`๋ฅผ ์‹คํ–‰ํ•˜์—ฌ ํ…Œ์ŠคํŠธ ํ™˜๊ฒฝ์„ ์‹คํ–‰ (K3s ๊ธฐ๋ฐ˜ Kubernetes ํ™˜๊ฒฝ)
- ์•…์„ฑ ์‰˜ ์ฝ”๋“œ๋ฅผ ์ปดํŒŒ์ผ
  ```
  gcc -shared -fPIC -o shell.so shell.c
  ```
- ์•„๋ž˜์˜ ๋ช…๋ น์–ด๋ฅผ ํ†ตํ•ด ์ทจ์•ฝ์  ์•…์šฉ
  ```
  python exploit.py -a https://localhost:30443/networking/v1/ingresses -i http://localhost:30080/fake/addr -s shell.so
  ```
### ์‹คํ–‰ ๊ฒฐ๊ณผ
![CVE-2025-1974](https://github.com/salt318/CVE-2025-1974/blob/main/CVE-2025-1974.png)

### ์ •๋ฆฌ
Ingress-NGINX Admission Controller์˜ ์ธ์ฆ ๋ถ€์žฌ ์ทจ์•ฝ์ ์€ ์•…์„ฑ Ingress ๋ฆฌ์†Œ์Šค๋ฅผ ์‚ฝ์ž…ํ•˜๊ฑฐ๋‚˜ ์‹œ์Šคํ…œ์„ ์ œ์–ดํ•˜๋Š” ํ–‰์œ„๋ฅผ ๊ฐ€๋Šฅํ•˜๊ฒŒ ํ•˜๋ฉฐ, ๋‹ค๋ฅธ ์ทจ์•ฝ์ ๊ณผ ์—ฐ๊ณ„๋  ๊ฒฝ์šฐ ์›๊ฒฉ ์ฝ”๋“œ ์‹คํ–‰(RCE)๋กœ ์ด์–ด์งˆ ์ˆ˜ ์žˆ๋‹ค. ๋”ฐ๋ผ์„œ Admission Controller ์ ‘๊ทผ์— ๋Œ€ํ•œ ์ธ์ฆ ๋ฐ ๊ถŒํ•œ ๊ฒ€์ฆ ๊ฐ•ํ™”, Ingress ๋ฆฌ์†Œ์Šค ๊ฒ€์ฆ ๋กœ์ง ๊ฐ•ํ™”, ๋„คํŠธ์›Œํฌ ACL(Access Control List) ์„ค์ •์„ ํ†ตํ•œ ์™ธ๋ถ€ ์ ‘๊ทผ ์ฐจ๋‹จ ๋“ฑ์˜ ๋ณด์•ˆ ์กฐ์น˜๋ฅผ ์ ์šฉํ•ด์•ผ ํ•œ๋‹ค.