GHSA-579h-mv94-g4gp

    Dashboard / Vulnerabilities / GHSA-579h-mv94-g4gp

    GHSA-579h-mv94-g4gp

    Published: 15 Feb 2022Last Modified: 10 Sept 2026

    Summary: Privilege Escalation in Kubernetes

    Details: In all Kubernetes versions prior to v1.10.11, v1.11.5, and v1.12.3, incorrect handling of error responses to proxied upgrade requests in the kube-apiserver allowed specially crafted requests to establish a connection through the Kubernetes API server to backend servers, then send arbitrary requests over the same connection directly to the backend, authenticated with the Kubernetes API server's TLS credentials used to establish the backend connection.

    Affected packages

    Package

    Name: github.com/kubernetes/kubernetes

    Purl: pkg:golang/github.com/kubernetes/kubernetes

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 0
    Fixed -1.10.11

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High