Confused Deputy in Kubernetes
Moderate severity
GitHub Reviewed
Published
Sep 21, 2021
to the GitHub Advisory Database
•
Updated Feb 1, 2023
Description
Published by the National Vulnerability Database
Sep 20, 2021
Reviewed
Sep 21, 2021
Published to the GitHub Advisory Database
Sep 21, 2021
Last updated
Feb 1, 2023
A security issue was discovered in Kubernetes where actors that control the responses of MutatingWebhookConfiguration or ValidatingWebhookConfiguration requests are able to redirect kube-apiserver requests to private networks of the apiserver. If that user can view kube-apiserver logs when the log level is set to 10, they can view the redirected responses and headers in the logs.
References