CVE-2021-25737
LOW severity · CVSS 2.7 · CWE-184
2.7CVSS LOW
Summary
A security issue was discovered in Kubernetes where a user may be able to redirect pod traffic to private networks on a Node. Kubernetes already prevents creation of Endpoint IPs in the localhost or link-local range, but the same validation was not performed on EndpointSlice IPs.
Impact & exploitability
Attack vectorNetwork
Attack complexityLow
Privileges requiredHigh
User interactionNone
Confidentiality impactLow
Integrity impactNone
Availability impactNone
Exploit probability (EPSS)0%
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N
Affected products we track (1)
Recommendation
Apply the vendor fix in your normal patch cycle. Open any affected product above for its exact safe version.
Official patch: https://github.com/kubernetes/kubernetes/issues/102106 ↗
Additional information
- NVD record
- https://github.com/kubernetes/kubernetes/issues/102106Patch
- https://github.com/kubernetes/kubernetes/issues/102106Patch
- https://groups.google.com/g/kubernetes-security-announce/c/xAiN3924thYAdvisory
- https://security.netapp.com/advisory/ntap-20211004-0004/Advisory
- https://groups.google.com/g/kubernetes-security-announce/c/xAiN3924thYAdvisory
- https://security.netapp.com/advisory/ntap-20211004-0004/Advisory