Lucene search

K
osvGoogleOSV:GHSA-J9WF-VVM6-4R9W
HistoryFeb 08, 2022 - 9:50 p.m.

Unverified Ownership in Kubernetes

2022-02-0821:50:34
Google
osv.dev
16
kubernetes
api
vulnerability
clusterip
service
externalips
traffic
loadbalancer
ingress.

EPSS

0.002

Percentile

62.1%

Kubernetes API server in all versions allow an attacker who is able to create a ClusterIP service and set the spec.externalIPs field, to intercept traffic to that IP address. Additionally, an attacker who is able to patch the status (which is considered a privileged operation and should not typically be granted to users) of a LoadBalancer service can set the status.loadBalancer.ingress.ip to similar effect.

References