GHSA-mfv7-gq43-w965
Dashboard / Vulnerabilities / GHSA-mfv7-gq43-w965
GHSA-mfv7-gq43-w965
Summary: Incomplete List of Disallowed Inputs in Kubernetes
Details: A security issue was discovered in Kubernetes where a user may be able to redirect pod traffic to private networks on a Node. Kubernetes already prevents creation of Endpoint IPs in the localhost or link-local range, but the same validation was not performed on EndpointSlice IPs.
References: https://nvd.nist.gov/vuln/detail/CVE-2021-25737, https://github.com/kubernetes/kubernetes/issues/102106, https://github.com/kubernetes/kubernetes, https://groups.google.com/g/kubernetes-security-announce/c/xAiN3924thY, https://security.netapp.com/advisory/ntap-20211004-0004
Affected packages
Package
Name: k8s.io/kubernetes
Purl: pkg:golang/k8s.io/kubernetes
Affected ranges
Type: SEMVER
Events:
