Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:25627
HistoryJun 08, 2020 - 4:06 a.m.

Server Side Request Forgery (SSRF)

2020-06-0804:06:12
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
23

EPSS

0.001

Percentile

41.5%

github.com/kubernetes/kubernetes is vulnerable to Server Side Request Forgery (SSRF). An attacker with a privilege to create a pod with certain built-in Volume types (GlusterFS, Quobyte, StorageFS, ScaleIO) or to create a StorageClass can cause an authenticated user to leak the resources from the endpoints without protection on the master’s host network.