Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:39496
HistoryMar 03, 2023 - 2:55 a.m.

Authentication Bypass

2023-03-0302:55:41
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
19
kubernetes
authentication bypass
resourcelocation
software
api server

EPSS

0.002

Percentile

57.8%

github.com/kubernetes/kubernetes is vulnerable to Authentication Bypass. The vulnerability exists because of improper node address validation in the ResourceLocation function of strategy.go, allowing an attacker to bypass the proxy address validation and send malicious requests to the API server’s private network.