Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-25740

Опубликовано: 15 июл. 2021
Источник: redhat
CVSS3: 3.1

Описание

A security issue was discovered with Kubernetes that could enable users to send network traffic to locations they would otherwise not have access to via a confused deputy attack.

A flaw was found in Kubernetes. This issue enables users to send network traffic to locations they would otherwise not have access to via a confused deputy attack.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenShift Container Platform 3.11atomic-openshiftOut of support scope
Red Hat OpenShift Container Platform 4openshiftNot affected

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-863
https://bugzilla.redhat.com/show_bug.cgi?id=1982470kubernetes: Endpoint & EndpointSlice permissions allow cross-Namespace forwarding

3.1 Low

CVSS3

Связанные уязвимости

CVSS3: 3.1
ubuntu
больше 3 лет назад

A security issue was discovered with Kubernetes that could enable users to send network traffic to locations they would otherwise not have access to via a confused deputy attack.

CVSS3: 3.1
nvd
больше 3 лет назад

A security issue was discovered with Kubernetes that could enable users to send network traffic to locations they would otherwise not have access to via a confused deputy attack.

CVSS3: 3.1
debian
больше 3 лет назад

A security issue was discovered with Kubernetes that could enable user ...

CVSS3: 3.1
github
больше 3 лет назад

Confused Deputy in Kubernetes

CVSS3: 3.1
fstec
почти 4 года назад

Уязвимость корпоративной платформы Red Hat OpenShift Container Platform, связанная с ошибками проведения процедуры авторизации, позволяющая нарушителю получить доступ к защищаемой информации

3.1 Low

CVSS3