CVE-2021-25735
06.09.2021, 12:15
A security issue was discovered in kube-apiserver that could allow node updates to bypass a Validating Admission Webhook. Clusters are only affected by this vulnerability if they run a Validating Admission Webhook for Nodes that denies admission based at least partially on the old state of the Node object. Validating Admission Webhook does not observe some previous fields.Enginsight
Vendor | Product | Version |
---|---|---|
kubernetes | kubernetes | 𝑥 < 1.18.18 |
kubernetes | kubernetes | 1.19.0 ≤ 𝑥 < 1.19.10 |
kubernetes | kubernetes | 1.20.0 ≤ 𝑥 < 1.20.6 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases