PT-2016-1271 · Kubernetes · Kubernetes

Deads2K

·

Published

2016-02-03

·

Updated

2024-08-21

·

CVE-2016-1905

CVSS v3.1

7.7

High

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Kubernetes (affected versions not specified)
Description The issue is related to insufficient access control in the Kubernetes API server, allowing remote authenticated users to access additional resources by crafting a patched object. This can lead to unauthorized access to protected information. The problem is associated with the admission control mechanism not being properly checked.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Access Control

Weakness Enumeration

Related Identifiers

BDU:2016-00544
CVE-2016-1905
GHSA-XX8C-M748-XR4J
GO-2022-0893
RHSA-2016:0070
RHSA-2016:0351

Affected Products

Kubernetes