Kubernetes API server in all versions allow an attacker who is able to create a ClusterIP service and set the spec.externalIPs field, to intercept traffic to that IP address. Additionally, an attacker who is able to patch the status (which is considered a privileged operation and should not typically be granted to users) of a LoadBalancer service can set the status.loadBalancer.ingress.ip to similar effect.
2021-01-21T17:15:13.843
2024-11-21T05:39:01.370
Modified
CVSSv3.1: 6.3 (MEDIUM)
AV:N/AC:M/Au:S/C:P/I:P/A:P
6.8
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | kubernetes | kubernetes | * | Yes |
Application | oracle | communications_cloud_native_core_network_slice_selection_function | 1.2.1 | Yes |
Application | oracle | communications_cloud_native_core_policy | 1.15.0 | Yes |
Application | oracle | communications_cloud_native_core_service_communication_proxy | 1.14.0 | Yes |