QID 377846

Date Published: 2023-01-30

QID 377846: Kubernetes Validating Admission Webhook Vulnerability

Kubernetes is an open-source container-orchestration system for automating deployment, scaling, and management of containerized applications.

Affected version:
kube-apiserver v1.20.0 - v1.20.5
kube-apiserver v1.19.0 - v1.19.9
kube-apiserver including and prior to v1.18.17
QID Detection Logic:(Authenticated)
The QID uses 'kubectl version' command to check for vulnerable versions of Kubernetes

Successful exploitation of the vulnerability may allow an attacker to node updates to bypass a Validating Admission Webhook

  • CVSS V3 rated as High - 6.5 severity.
  • CVSS V2 rated as Medium - 5.5 severity.
  • Solution
    For more information please visit 100096

    Workaround:
    This only impacts validating admission plugins that rely on old values in certain fields, and does not impact calls from kubelets that go through the built-in NodeRestriction admission plugin.

    CVEs related to QID 377846

    Software Advisories
    Advisory ID Software Component Link
    100096 URL Logo github.com/kubernetes/kubernetes/issues/100096