Improper validation of URL redirection in the Kubernetes API server in versions prior to v1.14.0 allows an attacker-controlled Kubelet to redirect API server requests from streaming endpoints to arbitrary hosts. Impacted API servers will follow the redirect as a GET request with client-certificate credentials for authenticating to the Kubelet.
2019-12-05T16:15:10.427
2024-11-21T03:40:38.570
Modified
CVSSv3.1: 2.6 (LOW)
AV:N/AC:H/Au:S/C:P/I:N/A:N
3.9
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | kubernetes | kubernetes | ≤ 1.13.13 | Yes |
Application | kubernetes | kubernetes | 1.14.0 | Yes |
Application | kubernetes | kubernetes | 1.14.0 | Yes |
Operating System | fedoraproject | fedora | 31 | Yes |