A security issue was discovered in kube-apiserver that could allow node updates to bypass a Validating Admission Webhook. Clusters are only affected by this vulnerability if they run a Validating Admission Webhook for Nodes that denies admission based at least partially on the old state of the Node object. Validating Admission Webhook does not observe some previous fields.
CVSS Details
- CVSS 3.1 Base Score: 6.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade k3s | Aug 22, 2024 | Sep 6, 2021 |
| Debian | — | Upgrade kubernetes | Jul 30, 2024 | Sep 6, 2021 |
| Kubernetes | — | Upgrade Kubernetes to version 1.20.6Upgrade Kubernetes to version 1.19.10Upgrade Kubernetes to version 1.18.18 | Mar 10, 2022 | Sep 6, 2021 |
| Redhat Openshift | — | Upgrade openshift | Jul 29, 2021 | Apr 14, 2021 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub