Gallery

Contacts

411 University St, Seattle, USA

engitech@oceanthemes.net

+1 -800-456-478-23

A critical vulnerability (CVSS 10.0) in the Azure Linux Ingress Controller for Kubernetes allows malformed Punycode-encoded domain labels to bypass hostname validation, enabling domain spoofing and security control circumvention. Organizations running Microsoft’s Azure Linux 3.0 application-gateway-kubernetes-ingress version 1.7.7-3 are affected. If exploited, attackers could redirect traffic, bypass access controls, or conduct man-in-the-middle attacks against Kubernetes-managed application workloads.

Author

Tech Jacks Solutions