QID 980534

QID 980534: Go (go) Security Update for k8s.io/kubernetes (GHSA-mfv7-gq43-w965)

A security issue was discovered in Kubernetes where a user may be able to redirect pod traffic to private networks on a Node. Kubernetes already prevents creation of Endpoint IPs in the localhost or link-local range, but the same validation was not performed on EndpointSlice IPs.

Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.

  • CVSS V3 rated as Medium - 4.8 severity.
  • CVSS V2 rated as Medium - 4.9 severity.
  • Solution
    Customers are advised to refer to GHSA-mfv7-gq43-w965 for updates pertaining to this vulnerability.
    Vendor References

    CVEs related to QID 980534

    Software Advisories
    Advisory ID Software Component Link
    GHSA-mfv7-gq43-w965 k8s.io/kubernetes URL Logo github.com/advisories/GHSA-mfv7-gq43-w965