Outage in Immuta

Immuta SaaS Response - Ingress Nightmare Vulnerability

Resolved Minor
March 26, 2025 - Started about 1 month ago - Lasted 2 days
Official incident page

Need to monitor Immuta outages?
Stay on top of outages with IsDown. Monitor the official status pages of all your vendors, SaaS, and tools, including Immuta, and never miss an outage again.
Start Free Trial

Outage Details

This notice is to inform you about a recently disclosed security vulnerability, known as "Ingress Nightmare," that affects certain Kubernetes Ingress configurations. While our SaaS solution utilizes Kubernetes, we have implemented controls to mitigate the potential impact of this vulnerability. What is the Ingress Nightmare Vulnerability (https://sysdig.com/blog/detecting-and-mitigating-ingressnightmare-cve-2025-1974/)? This vulnerability could, in certain scenarios, allow unauthorized access to services within a Kubernetes cluster. Impact on Our SaaS Solution: - We have existing security measures in place that limit the scope and potential impact of this vulnerability. - We are actively deploying updates to fully address and prevent this vulnerability. The deployment is scheduled for March 27th. Our Commitment to Security: - We conduct regular vulnerability scans to proactively identify and address security concerns. - Following the update deployment on March 27th, we will perform an immediate security scan to confirm the vulnerability has been completely resolved. Your security is our top priority. We are committed to maintaining a secure and reliable SaaS solution. If you have any questions or concerns, please don't hesitate to contact our support team.
Latest Updates ( sorted recent to last )
RESOLVED about 1 month ago - at 03/28/2025 01:54PM

This issue has been resolved. All updates have been performed to remove this vulnerability and additional policies have been in place to mitigate any exposure due to this type of exploit.

MONITORING about 1 month ago - at 03/26/2025 03:43PM

This notice is to inform you about a recently disclosed security vulnerability, known as "Ingress Nightmare," that affects certain Kubernetes Ingress configurations. While our SaaS solution utilizes Kubernetes, we have implemented controls to mitigate the potential impact of this vulnerability.

What is the Ingress Nightmare Vulnerability (https://sysdig.com/blog/detecting-and-mitigating-ingressnightmare-cve-2025-1974/)?
This vulnerability could, in certain scenarios, allow unauthorized access to services within a Kubernetes cluster.
Impact on Our SaaS Solution:
- We have existing security measures in place that limit the scope and potential impact of this vulnerability.
- We are actively deploying updates to fully address and prevent this vulnerability. The deployment is scheduled for March 27th.

Our Commitment to Security:
- We conduct regular vulnerability scans to proactively identify and address security concerns.
- Following the update deployment on March 27th, we will perform an immediate security scan to confirm the vulnerability has been completely resolved.

Your security is our top priority. We are committed to maintaining a secure and reliable SaaS solution. If you have any questions or concerns, please don't hesitate to contact our support team.

All Your Service Status Pages in One Dashboard

With IsDown, you can monitor all your critical services' official status pages from one centralized dashboard and receive instant alerts the moment an outage is detected. Say goodbye to constantly checking multiple sites for updates and stay ahead of outages with IsDown.

Start free trial

No credit card required · Cancel anytime · 4000 services available

Integrations with Slack Microsoft Teams Google Chat Datadog PagerDuty Zapier Discord Webhook