Server-side request forgery (SSRF) In k8s.io/kubernetes
Description
Privilege Escalation in Kubernetes The Kubernetes kube-apiserver in versions v1.6-v1.15, and versions prior to v1.16.13, v1.17.9 and v1.18.7 are vulnerable to an unvalidated redirect on proxied upgrade requests that could allow an attacker to escalate privileges from a node compromise to a full cluster compromise.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Component | Affected version | Patched versions |
|---|---|---|---|
go | 0.16.13, 0.17.9, 0.18.7 | ||
go | 1.16.13, 1.17.9, 1.18.7 | ||
go | 0.19.0-rc.1 | ||
debian 11 | 1.18.5-1 | ||
debian 12 | 1.18.5-1 | ||
debian 14 | 1.18.5-1 | ||
go | v1.18.6, v1.17.9 | ||
go | 1.16.13, 1.17.9, 1.18.6 | ||
debian 13 | 1.18.5-1 |
Aliases
1. 2. 3. 4. 5. 6.
References
1. 2. 3. 4. 5. 6. 7. 8.