Launch Week Day 1: Announcing Security Design Review
MEDIUM 4.1 Go

Confused Deputy in Kubernetes

GHSA-74j8-88mm-7496 · CVE-2020-8561

Published · Modified

Description

A security issue was discovered in Kubernetes where actors that control the responses of MutatingWebhookConfiguration or ValidatingWebhookConfiguration requests are able to redirect kube-apiserver requests to private networks of the apiserver. If that user can view kube-apiserver logs when the log level is set to 10, they can view the redirected responses and headers in the logs.

Ready to move

Start Securing

Free, no credit card | First findings in minutes