QID 980585

QID 980585: Go (go) Security Update for k8s.io/kubernetes (GHSA-74j8-88mm-7496)

A security issue was discovered in Kubernetes where actors that control the responses of MutatingWebhookConfiguration or ValidatingWebhookConfiguration requests are able to redirect kube-apiserver requests to private networks of the apiserver. If that user can view kube-apiserver logs when the log level is set to 10, they can view the redirected responses and headers in the logs.

Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.

  • CVSS V3 rated as Medium - 4.1 severity.
  • CVSS V2 rated as Medium - 4 severity.
  • Solution
    Customers are advised to refer to GHSA-74j8-88mm-7496 for updates pertaining to this vulnerability.
    Vendor References

    CVEs related to QID 980585

    Software Advisories
    Advisory ID Software Component Link
    GHSA-74j8-88mm-7496 k8s.io/kubernetes URL Logo github.com/advisories/GHSA-74j8-88mm-7496