Gallery

Contacts

405 W. Greenlawn Ave Lansing, Michigan 48910

contact@techjacksolutions.com

+1-616-320-4064

A critical vulnerability (CVSS 10.0) in the Azure Linux Ingress Controller for Kubernetes allows malformed Punycode-encoded domain labels to bypass hostname validation, enabling domain spoofing and security control circumvention. Organizations running Microsoft’s Azure Linux 3.0 application-gateway-kubernetes-ingress version 1.7.7-3 are affected. If exploited, attackers could redirect traffic, bypass access controls, or conduct man-in-the-middle attacks against Kubernetes-managed application workloads.

Author

Tech Jacks Solutions