Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-mxxc-p822-2hx9 | Skipper Ingress Controller Allows Unauthorized Access to Internal Services via ExternalName |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Tue, 27 Jan 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 27 Jan 2026 09:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Zalando
Zalando skipper |
|
| Vendors & Products |
Zalando
Zalando skipper |
Mon, 26 Jan 2026 22:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Skipper is an HTTP router and reverse proxy for service composition. Prior to version 0.24.0, when running Skipper as an Ingress controller, users with permissions to create an Ingress and a Service of type ExternalName can create routes that enable them to use Skipper's network access to reach internal services. Version 0.24.0 disables Kubernetes ExternalName by default. As a workaround, developers can allow list targets of an ExternalName and allow list via regular expressions. | |
| Title | Skipper Ingress Controller Allows Unauthorized Access to Internal Services via ExternalName | |
| Weaknesses | CWE-441 CWE-918 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-01-27T14:51:35.229Z
Reserved: 2026-01-23T00:38:20.546Z
Link: CVE-2026-24470
Updated: 2026-01-27T14:51:31.267Z
Status : Awaiting Analysis
Published: 2026-01-26T23:16:09.123
Modified: 2026-01-27T14:59:34.073
Link: CVE-2026-24470
No data.
OpenCVE Enrichment
Updated: 2026-01-27T09:03:12Z
Github GHSA