5.5
CVSSv2

CVE-2021-25735

Published: 06/09/2021 Updated: 26/06/2023
CVSS v2 Base Score: 5.5 | Impact Score: 4.9 | Exploitability Score: 8
CVSS v3 Base Score: 6.5 | Impact Score: 5.2 | Exploitability Score: 1.2
VMScore: 490
Vector: AV:N/AC:L/Au:S/C:N/I:P/A:P

Vulnerability Summary

A security issue exists in kube-apiserver that could allow node updates to bypass a Validating Admission Webhook. Clusters are only affected by this vulnerability if they run a Validating Admission Webhook for Nodes that denies admission based at least partially on the old state of the Node object. Validating Admission Webhook does not observe some previous fields.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

kubernetes kubernetes

Vendor Advisories

Synopsis Important: OpenShift Container Platform 41030 bug fix and security update Type/Severity Security Advisory: Important Topic Red Hat OpenShift Container Platform release 41030 is now available withupdates to packages and images that fix several bugs and add enhancementsThis release includes a security update for Red Hat OpenShift ...
Debian Bug report logs - #990793 kubernetes: CVE-2020-8554 CVE-2020-8562 CVE-2021-25735 CVE-2021-25737 Package: src:kubernetes; Maintainer for src:kubernetes is Janos Lenart <ocsi@debianorg>; Reported by: Moritz Mühlenhoff <jmm@inutilorg> Date: Wed, 7 Jul 2021 15:48:02 UTC Severity: important Tags: security, upst ...
A vulnerability was found in kube-apiserver that could allow node updates to bypass a Validating Admission Webhook The highest threat from this vulnerability is to integrity and availability ...
A security issue was discovered in kube-apiserver that could allow node updates to bypass a Validating Admission Webhook ...

Mailing Lists

<!--X-Body-Begin--> <!--X-User-Header--> oss-sec mailing list archives <!--X-User-Header-End--> <!--X-TopPNI--> By Date By Thread </form> <!--X-TopPNI-End--> <!--X-MsgBody--> <!--X-Subject-Header-Begin--> [kubernetes] CVE-2021-25735: Validating Admission Webhook does not observe some previous fields <!--X-Subject-Header-End--> <! ...

Github Repositories

Exploit CVE-2021-25735: Kubernetes Validating Admission Webhook Bypass

CVE-2021-25735 Exploit CVE-2021-25735: Kubernetes Validating Admission Webhook Bypass Set the Vulnerable Environment Let's start with running the script gencertssh to generate TLS certificates and keys bash gencertssh To deploy the admission controller you need to build the Docker container image locally, tag, and push the image to your Dockerhub using the below comma

A curated list of Falco related tools, frameworks, blogs, podcasts, and articles

awesome-falco A curated list of Falco related tools, frameworks and articles Contents πŸ’Ό Official Projects πŸ“‚ Repositories πŸ—’οΈ Docs πŸ“° Blogs 🐾 Community Repositories πŸ—ƒοΈ Blogs and Articles πŸ“Ή Videos πŸ“‘ Slides 🎀 Podcasts πŸ§ͺ Interactive Learning 🧰 IDE and Editor Integrations πŸ“‘ Support and Community πŸ’Š Develop and Contribute πŸ“† Learn and