QID 376958

Date Published: 2022-09-01

QID 376958: Kubernetes kube-Apiserver EndpointSlice Validation Vulnerability

Kubernetes is an open-source container-orchestration system for automating deployment, scaling, and management of containerized applications.

Affected version:
kube-Apiserver v1.21.0
kube-Apiserver v1.20.0 to 1.20.6
kube-Apiserver v1.19.0 to 1.19.10
kube-Apiserver 1.16.0 to 1.18.18 (Note: EndpointSlices were not enabled by default in 1.16-1.18)

QID Detection Logic:(Authenticated)
The QID uses 'kubectl version' command to check for vulnerable versions of Kubernetes

Successful exploitation of the vulnerability may allow an attacker to redirect pod traffic to private networks on a Node

  • CVSS V3 rated as Medium - 4.8 severity.
  • CVSS V2 rated as Medium - 4.9 severity.
  • Solution
    For more information please visit 102106

    CVEs related to QID 376958

    Software Advisories
    Advisory ID Software Component Link
    102106 URL Logo github.com/kubernetes/kubernetes/issues/102106