Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2021-25740

Опубликовано: 20 сент. 2021
Источник: debian

Описание

A security issue was discovered with Kubernetes that could enable users to send network traffic to locations they would otherwise not have access to via a confused deputy attack.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
kubernetesfixed1.20.5+really1.20.2-1package

Примечания

  • Server components no longer built since 1.20.5+really1.20.2-1, marking that as fixed version

  • The source package itself it still vulnerable, but custom rebuilds are not really a usecase here

  • https://www.openwall.com/lists/oss-security/2021/07/14/1

Связанные уязвимости

CVSS3: 3.1
ubuntu
больше 3 лет назад

A security issue was discovered with Kubernetes that could enable users to send network traffic to locations they would otherwise not have access to via a confused deputy attack.

CVSS3: 3.1
redhat
почти 4 года назад

A security issue was discovered with Kubernetes that could enable users to send network traffic to locations they would otherwise not have access to via a confused deputy attack.

CVSS3: 3.1
nvd
больше 3 лет назад

A security issue was discovered with Kubernetes that could enable users to send network traffic to locations they would otherwise not have access to via a confused deputy attack.

CVSS3: 3.1
github
больше 3 лет назад

Confused Deputy in Kubernetes

CVSS3: 3.1
fstec
почти 4 года назад

Уязвимость корпоративной платформы Red Hat OpenShift Container Platform, связанная с ошибками проведения процедуры авторизации, позволяющая нарушителю получить доступ к защищаемой информации