CVE-2020-8561
- EPSS 0.31%
- Published 20.09.2021 17:15:08
- Last modified 21.11.2024 05:39:02
A security issue was discovered in Kubernetes where actors that control the responses of MutatingWebhookConfiguration or ValidatingWebhookConfiguration requests are able to redirect kube-apiserver requests to private networks of the apiserver. If tha...
CVE-2021-25737
- EPSS 0.93%
- Published 06.09.2021 12:15:07
- Last modified 21.11.2024 05:55:19
A security issue was discovered in Kubernetes where a user may be able to redirect pod traffic to private networks on a Node. Kubernetes already prevents creation of Endpoint IPs in the localhost or link-local range, but the same validation was not p...
CVE-2021-25735
- EPSS 23.14%
- Published 06.09.2021 12:15:07
- Last modified 21.11.2024 05:55:19
A security issue was discovered in kube-apiserver that could allow node updates to bypass a Validating Admission Webhook. Clusters are only affected by this vulnerability if they run a Validating Admission Webhook for Nodes that denies admission base...
- EPSS 24.78%
- Published 21.01.2021 17:15:13
- Last modified 21.11.2024 05:39:01
Kubernetes API server in all versions allow an attacker who is able to create a ClusterIP service and set the spec.externalIPs field, to intercept traffic to that IP address. Additionally, an attacker who is able to patch the status (which is conside...
CVE-2020-8566
- EPSS 0.13%
- Published 07.12.2020 22:15:21
- Last modified 21.11.2024 05:39:02
In Kubernetes clusters using Ceph RBD as a storage provisioner, with logging level of at least 4, Ceph RBD admin secrets can be written to logs. This occurs in kube-controller-manager's logs during provisioning of Ceph RBD persistent claims. This aff...
CVE-2020-8565
- EPSS 0.06%
- Published 07.12.2020 22:15:21
- Last modified 21.11.2024 05:39:02
In Kubernetes, if the logging level is set to at least 9, authorization and bearer tokens will be written to log files. This can occur both in API server logs and client tool output like kubectl. This affects <= v1.19.3, <= v1.18.10, <= v1.17.13, < v...
CVE-2020-8564
- EPSS 0.05%
- Published 07.12.2020 22:15:21
- Last modified 21.11.2024 05:39:02
In Kubernetes clusters using a logging level of at least 4, processing a malformed docker config file will result in the contents of the docker config file being leaked, which can include pull secrets or other registry credentials. This affects < v1....
CVE-2020-8563
- EPSS 0.08%
- Published 07.12.2020 22:15:21
- Last modified 21.11.2024 05:39:02
In Kubernetes clusters using VSphere as a cloud provider, with a logging level set to 4 or above, VSphere cloud credentials will be leaked in the cloud controller manager's log. This affects < v1.19.3.
CVE-2020-8558
- EPSS 24.21%
- Published 27.07.2020 20:15:12
- Last modified 21.11.2024 05:39:01
The Kubelet and kube-proxy components in versions 1.1.0-1.16.10, 1.17.0-1.17.6, and 1.18.0-1.18.3 were found to contain a security issue which allows adjacent hosts to reach TCP and UDP services bound to 127.0.0.1 running on the node or in the node's...
CVE-2020-8557
- EPSS 0.13%
- Published 23.07.2020 17:15:12
- Last modified 21.11.2024 05:39:01
The Kubernetes kubelet component in versions 1.1-1.16.12, 1.17.0-1.17.8 and 1.18.0-1.18.5 do not account for disk usage by a pod which writes to its own /etc/hosts file. The /etc/hosts file mounted in a pod by kubelet is not included by the kubelet e...