QID 377841

Date Published: 2023-01-30

QID 377841: Kubernetes Node Address Proxying Vulnerability

Kubernetes is an open-source container-orchestration system for automating deployment, scaling, and management of containerized applications.

Affected version:
Kubernetes including and prior to v1.25.3
Kubernetes including and prior to v1.24.7
Kubernetes including and prior to v1.23.13
Kubernetes including and prior to v1.22.15
QID Detection Logic:(Authenticated)
The QID uses 'kubectl version' command to check for vulnerable versions of Kubernetes

Successful exploitation of the vulnerability may allow an attacker to break clients that depend on the nodes/proxy subresource, specifically if a kubelet advertises a localhost or link-local address to the Kubernetes control plane.

  • CVSS V3 rated as Low - 0 severity.
  • CVSS V2 rated as Medium - 3.5 severity.
  • Solution
    For more information please visit 113757

    CVEs related to QID 377841

    Software Advisories
    Advisory ID Software Component Link
    113757 URL Logo github.com/kubernetes/kubernetes/issues/113757