CVE-2021-25735

Name
CVE-2021-25735
Description
A security issue was discovered in kube-apiserver that could allow node updates to bypass a Validating Admission Webhook. Clusters are only affected by this vulnerability if they run a Validating Admission Webhook for Nodes that denies admission based at least partially on the old state of the Node object. Validating Admission Webhook does not observe some previous fields.
NVD Severity
medium
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
MISC https://groups.google.com/g/kubernetes-security-announce/c/FKAGqT4jx9Y
MISC https://github.com/kubernetes/kubernetes/issues/100096

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:kubernetes:kubernetes:*:*:*:*:*:*:*:* kubernetes >= None < 1.18.18
cpe:2.3:a:kubernetes:kubernetes:*:*:*:*:*:*:*:* kubernetes >= 1.19.0 < 1.19.10
cpe:2.3:a:kubernetes:kubernetes:*:*:*:*:*:*:*:* kubernetes >= 1.20.0 < 1.20.6

Vulnerable and fixed packages

Source package Branch Version Maintainer Status