Kube-proxy on Windows can unintentionally forward traffic to local processes listening on the same port (“spec.ports[*].port”) as a LoadBalancer Service when the LoadBalancer controller does not set the “status.loadBalancer.ingress[].ip” field. Clusters where the LoadBalancer controller sets the “status.loadBalancer.ingress[].ip” field are unaffected.
2023-10-30T03:15:07.653
2025-06-12T15:15:27.407
Modified
CVSSv3.1: 5.8 (MEDIUM)
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | kubernetes | kubernetes | < 1.18.18 | Yes |
| Application | kubernetes | kubernetes | < 1.19.10 | Yes |
| Application | kubernetes | kubernetes | < 1.20.6 | Yes |
| Operating System | microsoft | windows | - | No |