Uncontrolled external site redirect In kubernetes
Description
Improper validation of URL redirection in the Kubernetes API server in versions prior to v1.14.0 allows an attacker-controlled Kubelet to redirect API server requests from streaming endpoints to arbitrary hosts. Impacted API servers will follow the redirect as a GET request with client-certificate credentials for authenticating to the Kubelet.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Component | Affected version | Patched versions |
|---|---|---|---|
debian 12 | 1.17.4-1 | ||
debian 13 | 1.17.4-1 | ||
debian 14 | 1.17.4-1 | ||
debian 11 | 1.17.4-1 | ||
go | v1.14.0 |
Aliases
1. 2. 3. 4. 5. 6.
References
1.