Description
A security issue was discovered in Kubernetes where actors that control the responses of MutatingWebhookConfiguration or ValidatingWebhookConfiguration requests are able to redirect kube-apiserver requests to private networks of the apiserver. If that user can view kube-apiserver logs when the log level is set to 10, they can view the redirected responses and headers in the logs.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-2002 | A security issue was discovered in Kubernetes where actors that control the responses of MutatingWebhookConfiguration or ValidatingWebhookConfiguration requests are able to redirect kube-apiserver requests to private networks of the apiserver. If that user can view kube-apiserver logs when the log level is set to 10, they can view the redirected responses and headers in the logs. |
Github GHSA |
GHSA-74j8-88mm-7496 | Confused Deputy in Kubernetes |
References
History
No history.
Status: PUBLISHED
Assigner: kubernetes
Published:
Updated: 2024-09-16T22:29:49.855Z
Reserved: 2020-02-03T00:00:00.000Z
Link: CVE-2020-8561
No data.
Status : Modified
Published: 2021-09-20T17:15:08.187
Modified: 2024-11-21T05:39:02.050
Link: CVE-2020-8561
OpenCVE Enrichment
No data.
EUVD
Github GHSA