4.8
CVSSv3

CVE-2021-25737

Published: 06/09/2021 Updated: 07/10/2021
CVSS v2 Base Score: 4.9 | Impact Score: 4.9 | Exploitability Score: 6.8
CVSS v3 Base Score: 4.8 | Impact Score: 2.7 | Exploitability Score: 1.7
VMScore: 438
Vector: AV:N/AC:M/Au:S/C:P/I:P/A:N

Vulnerability Summary

A security issue exists in Kubernetes where a user may be able to redirect pod traffic to private networks on a Node. Kubernetes already prevents creation of Endpoint IPs in the localhost or link-local range, but the same validation was not performed on EndpointSlice IPs.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

kubernetes kubernetes

kubernetes kubernetes 1.21.0

Vendor Advisories

Synopsis Important: OpenShift Container Platform 41030 bug fix and security update Type/Severity Security Advisory: Important Topic Red Hat OpenShift Container Platform release 41030 is now available withupdates to packages and images that fix several bugs and add enhancementsThis release includes a security update for Red Hat OpenShift ...
Debian Bug report logs - #990793 kubernetes: CVE-2020-8554 CVE-2020-8562 CVE-2021-25735 CVE-2021-25737 Package: src:kubernetes; Maintainer for src:kubernetes is Janos Lenart <ocsi@debianorg>; Reported by: Moritz Mühlenhoff <jmm@inutilorg> Date: Wed, 7 Jul 2021 15:48:02 UTC Severity: important Tags: security, upst ...
A security issue was discovered in Kubernetes where an authorized user may be able to redirect traffic to private networks on a Node An untrusted user could exploit this by creating or modifying EndpointSlices to point to localhost or link-local addresses ...
A security issue was discovered in kube-apiserver before version 1211 where a user may be able to redirect pod traffic to private networks on a Node Kubernetes already prevents creation of Endpoint IPs in the localhost or link-local range, but the same validation was not performed on EndpointSlice IPs ...

Mailing Lists

<!--X-Body-Begin--> <!--X-User-Header--> oss-sec mailing list archives <!--X-User-Header-End--> <!--X-TopPNI--> By Date By Thread </form> <!--X-TopPNI-End--> <!--X-MsgBody--> <!--X-Subject-Header-Begin--> [kubernetes] CVE-2021-25737: Holes in EndpointSlice Validation Enable Host Network Hijack <!--X-Subject-Header-End--> <!--X-He ...