Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2021-25735

Опубликовано: 06 сент. 2021
Источник: debian
EPSS Средний

Описание

A security issue was discovered in kube-apiserver that could allow node updates to bypass a Validating Admission Webhook. Clusters are only affected by this vulnerability if they run a Validating Admission Webhook for Nodes that denies admission based at least partially on the old state of the Node object. Validating Admission Webhook does not observe some previous fields.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
kubernetesfixed1.20.5+really1.20.2-1package

Примечания

  • https://www.openwall.com/lists/oss-security/2021/04/14/1

  • https://github.com/kubernetes/kubernetes/issues/100096

  • Server components no longer built since 1.20.5+really1.20.2-1, marking that as fixed

EPSS

Процентиль: 95%
0.18453
Средний

Связанные уязвимости

CVSS3: 6.5
ubuntu
почти 4 года назад

A security issue was discovered in kube-apiserver that could allow node updates to bypass a Validating Admission Webhook. Clusters are only affected by this vulnerability if they run a Validating Admission Webhook for Nodes that denies admission based at least partially on the old state of the Node object. Validating Admission Webhook does not observe some previous fields.

CVSS3: 6.5
redhat
около 4 лет назад

A security issue was discovered in kube-apiserver that could allow node updates to bypass a Validating Admission Webhook. Clusters are only affected by this vulnerability if they run a Validating Admission Webhook for Nodes that denies admission based at least partially on the old state of the Node object. Validating Admission Webhook does not observe some previous fields.

CVSS3: 6.5
nvd
почти 4 года назад

A security issue was discovered in kube-apiserver that could allow node updates to bypass a Validating Admission Webhook. Clusters are only affected by this vulnerability if they run a Validating Admission Webhook for Nodes that denies admission based at least partially on the old state of the Node object. Validating Admission Webhook does not observe some previous fields.

CVSS3: 6.5
github
около 4 лет назад

Access Restriction Bypass in kube-apiserver

CVSS3: 6.5
fstec
больше 4 лет назад

Уязвимость компонента kube-apiserver программного средства управления кластерами виртуальных машин Kubernetes, позволяющая нарушителю нарушить целостность данных, а также вызвать отказ в обслуживании

EPSS

Процентиль: 95%
0.18453
Средний