Description
A security issue was discovered in Kubernetes where a user may be able to redirect pod traffic to private networks on a Node. Kubernetes already prevents creation of Endpoint IPs in the localhost or link-local range, but the same validation was not performed on EndpointSlice IPs.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-2095 | A security issue was discovered in Kubernetes where a user may be able to redirect pod traffic to private networks on a Node. Kubernetes already prevents creation of Endpoint IPs in the localhost or link-local range, but the same validation was not performed on EndpointSlice IPs. |
Github GHSA |
GHSA-mfv7-gq43-w965 | Incomplete List of Disallowed Inputs in Kubernetes |
References
History
No history.
Status: PUBLISHED
Assigner: kubernetes
Published:
Updated: 2024-09-16T21:04:34.209Z
Reserved: 2021-01-21T00:00:00.000Z
Link: CVE-2021-25737
No data.
Status : Modified
Published: 2021-09-06T12:15:07.673
Modified: 2024-11-21T05:55:19.310
Link: CVE-2021-25737
OpenCVE Enrichment
No data.
EUVD
Github GHSA