Improper authorization control for web services In github.com/kubernetes/kubernetes
Description
Access Restriction Bypass in kubernetes The API server in Kubernetes does not properly check admission control, which allows remote authenticated users to access additional resources via a crafted patched object.
Specific Go Packages Affected
github.com/kubernetes/kubernetes/pkg/apiserver
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Component | Affected version | Patched versions |
|---|---|---|---|
go | v1.2.0 | ||
go | 1.2.0-alpha.6 | ||
go | 1.2.0-alpha.6 | ||
rpm rhel7 | - | - |
Aliases
1. 2. 3. 4. 5. 6. 7. 8.
References
1. 2. 3.