HIGH 7.7 Go
Access Restriction Bypass in kubernetes
GHSA-xx8c-m748-xr4j · CVE-2016-1905 · GO-2022-0893
Published · Modified
Description
The API server in Kubernetes does not properly check admission control, which allows remote authenticated users to access additional resources via a crafted patched object.
Specific Go Packages Affected
github.com/kubernetes/kubernetes/pkg/apiserver
References
- ADVISORY https://nvd.nist.gov/vuln/detail/CVE-2016-1905
- WEB https://github.com/kubernetes/kubernetes/issues/19479
- WEB https://github.com/kubernetes/kubernetes/commit/9e6912384a5bc714f2a780b870944a8cee264a22
- WEB https://access.redhat.com/errata/RHSA-2016:0070
- WEB https://access.redhat.com/errata/RHSA-2016:0351
- WEB https://access.redhat.com/security/cve/CVE-2016-1905
- WEB https://bugzilla.redhat.com/show_bug.cgi?id=1297910
Ready to move
Start Securing
Free, no credit card | First findings in minutes