QID 377854

Date Published: 2023-01-05

QID 377854: Kubernetes kube-Apiserver Privilege Escalation Vulnerability

Kubernetes is an open-source container-orchestration system for automating deployment, scaling, and management of containerized applications.

Affected version:
kube-apiserver v1.18.0-1.18.5
kube-apiserver v1.17.0-1.17.8
kube-apiserver v1.16.0-1.16.12
all kube-apiserver versions prior to v1.16.0
QID Detection Logic:(Authenticated)
The QID uses 'kubectl version' command to check for vulnerable versions of Kubernetes

Successful exploitation of the vulnerability may allow an attacker to send a redirect response that may be followed by a client using the credentials from the original request

  • CVSS V3 rated as High - 6.8 severity.
  • CVSS V2 rated as High - 6 severity.
  • Solution
    For more information please visit 92914

    CVEs related to QID 377854

    Software Advisories
    Advisory ID Software Component Link
    92914 URL Logo github.com/kubernetes/kubernetes/issues/92914