A security issue was discovered in Kubernetes where a user may be able to redirect pod traffic to private networks on a Node. Kubernetes already prevents creation of Endpoint IPs in the localhost or link-local range, but the same validation was not performed on EndpointSlice IPs.
Advisories
Source ID Title
EUVD EUVD EUVD-2021-2095 A security issue was discovered in Kubernetes where a user may be able to redirect pod traffic to private networks on a Node. Kubernetes already prevents creation of Endpoint IPs in the localhost or link-local range, but the same validation was not performed on EndpointSlice IPs.
Github GHSA Github GHSA GHSA-mfv7-gq43-w965 Incomplete List of Disallowed Inputs in Kubernetes
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: kubernetes

Published:

Updated: 2024-09-16T21:04:34.209Z

Reserved: 2021-01-21T00:00:00

Link: CVE-2021-25737

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2021-09-06T12:15:07.673

Modified: 2024-11-21T05:55:19.310

Link: CVE-2021-25737

cve-icon Redhat

Severity : Low

Publid Date: 2021-05-18T00:00:00Z

Links: CVE-2021-25737 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses