QID 376962

Date Published: 2022-09-06

QID 376962: Kubernetes kube-Controller-Manager Server Side Request Forgery (SSRF) Vulnerability

Kubernetes is an open-source container-orchestration system for automating deployment, scaling, and management of containerized applications.

Affected version:
kube-controller-manager v1.18.0
kube-controller-manager v1.17.0 to 1.17.4
kube-controller-manager v1.16.0 to 1.16.8
kube-controller-manager prior to v1.15.11

QID Detection Logic:(Authenticated)
The QID uses 'kubectl version' command to check for vulnerable versions of Kubernetes

Successful exploitation of the vulnerability may allow an attacker to authorized users to leak up to 500 bytes of arbitrary information from unprotected endpoints within the master's host network

  • CVSS V3 rated as High - 6.3 severity.
  • CVSS V2 rated as Medium - 3.5 severity.
  • Solution
    For more information please visit 91542

    CVEs related to QID 376962

    Software Advisories
    Advisory ID Software Component Link
    91542 URL Logo github.com/kubernetes/kubernetes/issues/91542