Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-25735

Опубликовано: 06 сент. 2021
Источник: nvd
CVSS3: 6.5
CVSS2: 5.5
EPSS Средний

Описание

A security issue was discovered in kube-apiserver that could allow node updates to bypass a Validating Admission Webhook. Clusters are only affected by this vulnerability if they run a Validating Admission Webhook for Nodes that denies admission based at least partially on the old state of the Node object. Validating Admission Webhook does not observe some previous fields.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:kubernetes:kubernetes:*:*:*:*:*:*:*:*
Версия до 1.18.18 (исключая)
cpe:2.3:a:kubernetes:kubernetes:*:*:*:*:*:*:*:*
Версия от 1.19.0 (включая) до 1.19.10 (исключая)
cpe:2.3:a:kubernetes:kubernetes:*:*:*:*:*:*:*:*
Версия от 1.20.0 (включая) до 1.20.6 (исключая)

EPSS

Процентиль: 95%
0.18453
Средний

6.5 Medium

CVSS3

5.5 Medium

CVSS2

Дефекты

CWE-372
NVD-CWE-Other

Связанные уязвимости

CVSS3: 6.5
ubuntu
почти 4 года назад

A security issue was discovered in kube-apiserver that could allow node updates to bypass a Validating Admission Webhook. Clusters are only affected by this vulnerability if they run a Validating Admission Webhook for Nodes that denies admission based at least partially on the old state of the Node object. Validating Admission Webhook does not observe some previous fields.

CVSS3: 6.5
redhat
около 4 лет назад

A security issue was discovered in kube-apiserver that could allow node updates to bypass a Validating Admission Webhook. Clusters are only affected by this vulnerability if they run a Validating Admission Webhook for Nodes that denies admission based at least partially on the old state of the Node object. Validating Admission Webhook does not observe some previous fields.

CVSS3: 6.5
debian
почти 4 года назад

A security issue was discovered in kube-apiserver that could allow nod ...

CVSS3: 6.5
github
около 4 лет назад

Access Restriction Bypass in kube-apiserver

CVSS3: 6.5
fstec
больше 4 лет назад

Уязвимость компонента kube-apiserver программного средства управления кластерами виртуальных машин Kubernetes, позволяющая нарушителю нарушить целостность данных, а также вызвать отказ в обслуживании

EPSS

Процентиль: 95%
0.18453
Средний

6.5 Medium

CVSS3

5.5 Medium

CVSS2

Дефекты

CWE-372
NVD-CWE-Other