[GO-2024-2748] Privilege Escalation in Kubernetes in k8s.io/apimachinery
Severity
Medium
Affected Packages
6
Fixed Packages
6
CVEs
1
The Kubernetes kube-apiserver is vulnerable to an unvalidated redirect on
proxied upgrade requests that could allow an attacker to escalate privileges
from a node compromise to a full cluster compromise.
Package | Affected Version |
---|---|
pkg:golang/k8s.io/apimachinery/pkg/util/proxy | >= 0.18.6, < 0.16.13 |
pkg:golang/k8s.io/apimachinery/pkg/util/proxy | >= 0.18.6, < 0.17.9 |
pkg:golang/k8s.io/apimachinery/pkg/util/proxy | >= 0.18.6, < 0.18.7-rc.0 |
pkg:golang/k8s.io/apimachinery/pkg/util/net | >= 0.18.6, < 0.16.13 |
pkg:golang/k8s.io/apimachinery/pkg/util/net | >= 0.18.6, < 0.17.9 |
pkg:golang/k8s.io/apimachinery/pkg/util/net | >= 0.18.6, < 0.18.7-rc.0 |
Package | Fixed Version |
---|---|
pkg:golang/k8s.io/apimachinery/pkg/util/proxy | = 0.16.13 |
pkg:golang/k8s.io/apimachinery/pkg/util/proxy | = 0.17.9 |
pkg:golang/k8s.io/apimachinery/pkg/util/proxy | = 0.18.7-rc.0 |
pkg:golang/k8s.io/apimachinery/pkg/util/net | = 0.16.13 |
pkg:golang/k8s.io/apimachinery/pkg/util/net | = 0.17.9 |
pkg:golang/k8s.io/apimachinery/pkg/util/net | = 0.18.7-rc.0 |
- ID
- GO-2024-2748
- Severity
- medium
- Severity from
- CVE-2020-8559
- URL
- https://pkg.go.dev/vuln/GO-2024-2748
- Published
-
2024-05-17T20:06:00
(4 months ago) - Modified
-
2024-07-17T19:54:18
(2 months ago) - Other Advisories
Source | # ID | Name | URL |
---|---|---|---|
Security Advisory | https://github.com/advisories/GHSA-33c5-9fx5-fvjm |
Type | Package URL | Namespace | Name / Product | Version | Distribution / Platform | Arch | Patch / Fix |
---|---|---|---|---|---|---|---|
Fixed | pkg:golang/k8s.io/apimachinery/pkg/util/proxy | k8s.io/apimachinery/pkg/util | proxy | = 0.16.13 | |||
Affected | pkg:golang/k8s.io/apimachinery/pkg/util/proxy | k8s.io/apimachinery/pkg/util | proxy | >= 0.18.6 < 0.16.13 | |||
Fixed | pkg:golang/k8s.io/apimachinery/pkg/util/proxy | k8s.io/apimachinery/pkg/util | proxy | = 0.17.9 | |||
Affected | pkg:golang/k8s.io/apimachinery/pkg/util/proxy | k8s.io/apimachinery/pkg/util | proxy | >= 0.18.6 < 0.17.9 | |||
Fixed | pkg:golang/k8s.io/apimachinery/pkg/util/proxy | k8s.io/apimachinery/pkg/util | proxy | = 0.18.7-rc.0 | |||
Affected | pkg:golang/k8s.io/apimachinery/pkg/util/proxy | k8s.io/apimachinery/pkg/util | proxy | >= 0.18.6 < 0.18.7-rc.0 | |||
Fixed | pkg:golang/k8s.io/apimachinery/pkg/util/net | k8s.io/apimachinery/pkg/util | net | = 0.16.13 | |||
Affected | pkg:golang/k8s.io/apimachinery/pkg/util/net | k8s.io/apimachinery/pkg/util | net | >= 0.18.6 < 0.16.13 | |||
Fixed | pkg:golang/k8s.io/apimachinery/pkg/util/net | k8s.io/apimachinery/pkg/util | net | = 0.17.9 | |||
Affected | pkg:golang/k8s.io/apimachinery/pkg/util/net | k8s.io/apimachinery/pkg/util | net | >= 0.18.6 < 0.17.9 | |||
Fixed | pkg:golang/k8s.io/apimachinery/pkg/util/net | k8s.io/apimachinery/pkg/util | net | = 0.18.7-rc.0 | |||
Affected | pkg:golang/k8s.io/apimachinery/pkg/util/net | k8s.io/apimachinery/pkg/util | net | >= 0.18.6 < 0.18.7-rc.0 |
# CVE | Description | CVSS | EPSS | EPSS Trend (30 days) | Affected Products | Weaknesses | Security Advisories | Exploits | PoC | Pubblication Date | Modification Date |
---|---|---|---|---|---|---|---|---|---|---|---|
# CVE | Description | CVSS | EPSS | EPSS Trend (30 days) | Affected Products | Weaknesses | Security Advisories | PoC | Pubblication Date | Modification Date |