QID 377835
Date Published: 2023-01-04
QID 377835: Bypass of Kubernetes API Server Proxy Vulnerability
Kubernetes is an open-source container-orchestration system for automating deployment, scaling, and management of containerized applications.
Affected version:
Kubernetes 1.21.0
Kubernetes 1.20.x up to and including v1.20.6
Kubernetes 1.19 up to and including v1.19.10
Kubernetes all version prior to and including v1.18.18
QID Detection Logic:(Authenticated)
The QID uses 'kubectl version' command to check for vulnerable versions of Kubernetes
Successful exploitation of the vulnerability may allow an attacker to an untrusted user can create or modify Node objects and proxy to them, or an untrusted user can create or modify StorageClass objects and access KubeControllerManager logs.
Workaround:
If this issue affects your clusters control planes, you can use dnsmasq for name resolution and configure the min-cache-ttl and neg-ttl parameters to a low non-zero value to enforce cached replies for proxied connections.
CVEs related to QID 377835
| Advisory ID | Software | Component | Link |
|---|