QID 376958
Date Published: 2022-09-01
QID 376958: Kubernetes kube-Apiserver EndpointSlice Validation Vulnerability
Kubernetes is an open-source container-orchestration system for automating deployment, scaling, and management of containerized applications.
Affected version:
kube-Apiserver v1.21.0
kube-Apiserver v1.20.0 to 1.20.6
kube-Apiserver v1.19.0 to 1.19.10
kube-Apiserver 1.16.0 to 1.18.18 (Note: EndpointSlices were not enabled by default in 1.16-1.18)
QID Detection Logic:(Authenticated)
The QID uses 'kubectl version' command to check for vulnerable versions of Kubernetes
Successful exploitation of the vulnerability may allow an attacker to redirect pod traffic to private networks on a Node
Solution
For more information please visit 102106
Vendor References
CVEs related to QID 376958
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| 102106 |
|