Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

msrc логотип

CVE-2021-1677

Опубликовано: 12 янв. 2021
Источник: msrc
CVSS3: 5.5
EPSS Низкий

Описание

Azure Active Directory Pod Identity Spoofing Vulnerability

FAQ

What can an attacker do with this vulnerability?

The AAD pod identity enables users to assign identities to pods in Kubernetes clusters and fetch them from the pods using a regular IMDS (Azure Instance Metadata Service) request. When an identity is assigned to a pod, the pod can access to the IMDS endpoint and get a token of that identity. An attacker who successfully exploited this vulnerability can laterally steal the identities that are associated with different pods.

How do I know if I need to install the update?

Customers with existing installation need to re-deploy their cluster and use Azure CNI instead of the default kubernet.

For more information, please see details here:

New installations will already have the update installed.

Обновления

ПродуктСтатьяОбновление
Microsoft Azure Kubernetes Service

Показывать по

Возможность эксплуатации

Publicly Disclosed

No

Exploited

No

Latest Software Release

Exploitation Less Likely

Older Software Release

Exploitation Less Likely

DOS

N/A

EPSS

Процентиль: 65%
0.00484
Низкий

5.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.5
nvd
около 5 лет назад

Azure Active Directory Pod Identity Spoofing Vulnerability

CVSS3: 5.5
github
больше 3 лет назад

Azure Active Directory Pod Identity Spoofing Vulnerability

CVSS3: 5.5
fstec
около 5 лет назад

Уязвимость службы Microsoft Azure Kubernetes операционной системы Windows, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

EPSS

Процентиль: 65%
0.00484
Низкий

5.5 Medium

CVSS3