Description
A security issue was discovered in Kubernetes where actors that control the responses of MutatingWebhookConfiguration or ValidatingWebhookConfiguration requests are able to redirect kube-apiserver requests to private networks of the apiserver. If that user can view kube-apiserver logs when the log level is set to 10, they can view the redirected responses and headers in the logs.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-2002 | A security issue was discovered in Kubernetes where actors that control the responses of MutatingWebhookConfiguration or ValidatingWebhookConfiguration requests are able to redirect kube-apiserver requests to private networks of the apiserver. If that user can view kube-apiserver logs when the log level is set to 10, they can view the redirected responses and headers in the logs. |
Github GHSA |
GHSA-74j8-88mm-7496 | Confused Deputy in Kubernetes |
References
History
Mon, 01 Jun 2026 22:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Status: PUBLISHED
Assigner: kubernetes
Published:
Updated: 2026-06-01T21:45:29.198Z
Reserved: 2020-02-03T00:00:00.000Z
Link: CVE-2020-8561
No data.
Status : Modified
Published: 2021-09-20T17:15:08.187
Modified: 2026-06-01T23:16:14.780
Link: CVE-2020-8561
OpenCVE Enrichment
No data.
EUVD
Github GHSA