QID 376851

Date Published: 2022-08-23

QID 376851: Kubernetes kube-Apiserver Privilege Escalation Vulnerability

Kubernetes is an open-source container-orchestration system for automating deployment, scaling, and management of containerized applications.
Affected version:
kubelet v1.18.0 to 1.18.5
kubelet v1.17.0 to 1.17.8
kubelet Prior to 1.16.13

QID Detection Logic:(Authenticated)
The QID uses 'kubectl version' command to check for vulnerable versions of Kubernetes

Successful exploitation of the vulnerability may allow an attacker to intercept certain requests to the Kubelet, they can send a redirect response that may be followed by a client using the credentials from the original request. This can lead to the compromise of other nodes.

  • CVSS V3 rated as High - 6.8 severity.
  • CVSS V2 rated as High - 6 severity.
  • Solution
    For more information please visit 92914

    CVEs related to QID 376851

    Software Advisories
    Advisory ID Software Component Link
    92914 URL Logo github.com/kubernetes/kubernetes/issues/92914