GHSA-33c5-9fx5-fvjm

Suggest an improvement
Source
https://github.com/advisories/GHSA-33c5-9fx5-fvjm
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/04/GHSA-33c5-9fx5-fvjm/GHSA-33c5-9fx5-fvjm.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-33c5-9fx5-fvjm
Aliases
Related
Published
2024-04-24T20:01:22Z
Modified
2024-10-15T05:56:58.433833Z
Severity
  • 6.8 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H CVSS Calculator
Summary
Privilege Escalation in Kubernetes
Details

The Kubernetes kube-apiserver in versions v1.6-v1.15, and versions prior to v1.16.13, v1.17.9 and v1.18.7 are vulnerable to an unvalidated redirect on proxied upgrade requests that could allow an attacker to escalate privileges from a node compromise to a full cluster compromise.

References

Affected packages

Go / k8s.io/apimachinery

Package

Name
k8s.io/apimachinery
View open source insights on deps.dev
Purl
pkg:golang/k8s.io/apimachinery

Affected ranges

Type
SEMVER
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.16.13

Go / k8s.io/apimachinery

Package

Name
k8s.io/apimachinery
View open source insights on deps.dev
Purl
pkg:golang/k8s.io/apimachinery

Affected ranges

Type
SEMVER
Events
Introduced
0.17.0
Fixed
0.17.9

Go / k8s.io/apimachinery

Package

Name
k8s.io/apimachinery
View open source insights on deps.dev
Purl
pkg:golang/k8s.io/apimachinery

Affected ranges

Type
SEMVER
Events
Introduced
0.18.0
Fixed
0.18.7

Go / k8s.io/kubernetes

Package

Name
k8s.io/kubernetes
View open source insights on deps.dev
Purl
pkg:golang/k8s.io/kubernetes

Affected ranges

Type
SEMVER
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.16.13

Go / k8s.io/kubernetes

Package

Name
k8s.io/kubernetes
View open source insights on deps.dev
Purl
pkg:golang/k8s.io/kubernetes

Affected ranges

Type
SEMVER
Events
Introduced
1.17.0
Fixed
1.17.9

Go / k8s.io/kubernetes

Package

Name
k8s.io/kubernetes
View open source insights on deps.dev
Purl
pkg:golang/k8s.io/kubernetes

Affected ranges

Type
SEMVER
Events
Introduced
1.18.0
Fixed
1.18.7