CVE-2021-25735

Aliases:GHSA-g42g-737j-qx6jGO-2022-0907
Advisory lineage Upstream: 0 Downstream: 4
Modified
Published: 06 Sept 2021, 11:32
Last modified:16 Sept 2024, 23:40

Vulnerability Summary

Overall Risk (default)
medium
29/100
CVSS Score
6.5 MEDIUM
v3.1 (cve.org)
EPSS Score
16.3% MEDIUM
16% probability +0.72%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

06 Sept 2021, 11:32
Published
Vulnerability first disclosed
16 Sept 2024, 23:40
Last Modified
Vulnerability information updated

Description

A security issue was discovered in kube-apiserver that could allow node updates to bypass a Validating Admission Webhook. Clusters are only affected by this vulnerability if they run a Validating Admission Webhook for Nodes that denies admission based at least partially on the old state of the Node object. Validating Admission Webhook does not observe some previous fields.

CVSS Metrics

  • v3.1MEDIUMScore: 6.5CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H
  • v2.0MEDIUMScore: 5.5AV:N/AC:L/Au:S/C:N/I:P/A:P

EPSS Trends

Current EPSS score: 16.30% Percentile: 95%

Techniques & Countermeasures

  • CWE-372Incomplete Internal State Distinction

    The product does not properly determine which state it is in, causing it to assume it is in state X when in fact it is in state Y, causing it to perform incorrect operations in a security-relevant manner.

Affected Systems

  • k8s.iokubernetes

    ≥ 1.19.0, < 1.19.10 | < 1.18.18 | ≥ 1.20.0, < 1.20.6

  • kuberneteskubernetes

    < 1.18.18 | ≥ 1.19.0, < 1.19.10 | ≥ 1.20.0, < 1.20.6 | ≥ unspecified, ≤ 1.18.17 | ≥ unspecified, ≤ 1.19.9 | ≥ unspecified, ≤ 1.20.5

References (10)