Impact
The maclof kubernetes-client library versions 0.17.0 through 0.31.99 disable TLS certificate verification in its kubeconfig parsing routines when the configuration lacks the certificate-authority-data field, and they also ignore the insecure-skip-tls-verify flag. This flaw allows an attacker who can observe or influence network traffic to impersonate the Kubernetes API server, tricking the client into trusting an invalid or malicious TLS certificate. The client will then authenticate with the API server and transmit bearer tokens or Basic credentials, which the attacker can capture. With those credentials, the attacker can read, write, or tamper with REST and WebSocket API traffic, effectively gaining the same permissions as the compromised token.
Affected Systems
The vulnerability affects the maclof:kubernetes-client package in all releases before 0.32.0, including version 0.17.0 up to 0.31.99. The client is used by any application or script that communicates with a Kubernetes cluster through this library, so any such application may be vulnerable if it relies on the affected package and a kubeconfig lacking a CA data field. All systems that import the library and use kubeconfigs that do not contain certificate-authority-data or that depend on the insecure-skip-tls-verify setting are at risk.
Risk and Exploitability
The CVSS score of 9.1 signals a high severity vulnerability. Because an EPSS score is not provided and the issue is not listed in the CISA Known Exploited Vulnerabilities catalog, it does not appear to be actively exploited at this time. Nevertheless, the attack requires an on‑path or network intruder who can present a rogue TLS certificate or substitute the Kubernetes API server. Once this precondition is met, no user interaction is needed; the client will automatically trust the counterfeit server and supply credentials, giving the attacker full access to the cluster resources protected by those credentials. The combination of a high threat score and the low effort required to set up a man‑in‑the‑middle attack in environments where network segmentation is weak means the risk to affected systems is significant, especially in production clusters.
OpenCVE Enrichment