Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-j9wf-vvm6-4r9w

Опубликовано: 08 фев. 2022
Источник: github
Github: Прошло ревью
CVSS3: 5

Описание

Unverified Ownership in Kubernetes

Kubernetes API server in all versions allow an attacker who is able to create a ClusterIP service and set the spec.externalIPs field, to intercept traffic to that IP address. Additionally, an attacker who is able to patch the status (which is considered a privileged operation and should not typically be granted to users) of a LoadBalancer service can set the status.loadBalancer.ingress.ip to similar effect.

Пакеты

Наименование

k8s.io/kubernetes

go
Затронутые версииВерсия исправления

<= 1.22.0

Отсутствует

EPSS

Процентиль: 96%
0.30412
Средний

5 Medium

CVSS3

Дефекты

CWE-283

Связанные уязвимости

CVSS3: 6.3
ubuntu
больше 4 лет назад

Kubernetes API server in all versions allow an attacker who is able to create a ClusterIP service and set the spec.externalIPs field, to intercept traffic to that IP address. Additionally, an attacker who is able to patch the status (which is considered a privileged operation and should not typically be granted to users) of a LoadBalancer service can set the status.loadBalancer.ingress.ip to similar effect.

CVSS3: 6.3
redhat
больше 4 лет назад

Kubernetes API server in all versions allow an attacker who is able to create a ClusterIP service and set the spec.externalIPs field, to intercept traffic to that IP address. Additionally, an attacker who is able to patch the status (which is considered a privileged operation and should not typically be granted to users) of a LoadBalancer service can set the status.loadBalancer.ingress.ip to similar effect.

CVSS3: 6.3
nvd
больше 4 лет назад

Kubernetes API server in all versions allow an attacker who is able to create a ClusterIP service and set the spec.externalIPs field, to intercept traffic to that IP address. Additionally, an attacker who is able to patch the status (which is considered a privileged operation and should not typically be granted to users) of a LoadBalancer service can set the status.loadBalancer.ingress.ip to similar effect.

CVSS3: 5
msrc
больше 1 года назад

Описание отсутствует

CVSS3: 6.3
debian
больше 4 лет назад

Kubernetes API server in all versions allow an attacker who is able to ...

EPSS

Процентиль: 96%
0.30412
Средний

5 Medium

CVSS3

Дефекты

CWE-283