QID 376851
Date Published: 2022-08-23
QID 376851: Kubernetes kube-Apiserver Privilege Escalation Vulnerability
Kubernetes is an open-source container-orchestration system for automating deployment, scaling, and management of containerized applications.
Affected version:
kubelet v1.18.0 to 1.18.5
kubelet v1.17.0 to 1.17.8
kubelet Prior to 1.16.13
QID Detection Logic:(Authenticated)
The QID uses 'kubectl version' command to check for vulnerable versions of Kubernetes
Successful exploitation of the vulnerability may allow an attacker to intercept certain requests to the Kubelet, they can send a redirect response that may be followed by a client using the credentials from the original request. This can lead to the compromise of other nodes.
Solution
For more information please visit 92914
Vendor References
CVEs related to QID 376851
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| 92914 |
|