UBUNTU-CVE-2021-25735
Dashboard / Vulnerabilities / UBUNTU-CVE-2021-25735
Summary:
Details: A security issue was discovered in kube-apiserver that could allow node updates to bypass a Validating Admission Webhook. Clusters are only affected by this vulnerability if they run a Validating Admission Webhook for Nodes that denies admission based at least partially on the old state of the Node object. Validating Admission Webhook does not observe some previous fields.
References: https://ubuntu.com/security/CVE-2021-25735, https://www.openwall.com/lists/oss-security/2021/04/14/1, https://github.com/kubernetes/kubernetes/issues/100096, https://www.cve.org/CVERecord?id=CVE-2021-25735
Affected packages
Package
Name: kubernetes
Purl: pkg:deb/ubuntu/[email protected]?arch=source&distro=esm-apps/focal
Affected ranges
Type: ECOSYSTEM
Events:
