A security issue was discovered in kube-apiserver that could allow node updates to bypass a Validating Admission Webhook. Clusters are only affected by this vulnerability if they run a Validating Admission Webhook for Nodes that denies admission based at least partially on the old state of the Node object. Validating Admission Webhook does not observe some previous fields.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: kubernetes

Published: 2021-09-06T11:32:00.853331Z

Updated: 2024-09-16T23:40:25.902Z

Reserved: 2021-01-21T00:00:00

Link: CVE-2021-25735

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2021-09-06T12:15:07.617

Modified: 2023-06-26T19:16:31.153

Link: CVE-2021-25735

cve-icon Redhat

Severity : Moderate

Publid Date: 2021-04-14T00:00:00Z

Links: CVE-2021-25735 - Bugzilla