Lucene search

K
osvGoogleOSV:GHSA-579H-MV94-G4GP
HistoryFeb 15, 2022 - 1:57 a.m.

Privilege Escalation in Kubernetes

2022-02-1501:57:18
Google
osv.dev
22

0.352 Low

EPSS

Percentile

97.2%

In all Kubernetes versions prior to v1.10.11, v1.11.5, and v1.12.3, incorrect handling of error responses to proxied upgrade requests in the kube-apiserver allowed specially crafted requests to establish a connection through the Kubernetes API server to backend servers, then send arbitrary requests over the same connection directly to the backend, authenticated with the Kubernetes API serverโ€™s TLS credentials used to establish the backend connection.

References