PT-2018-15591 · Sap · Gardener

Published

2018-10-09

·

Updated

2020-08-24

·

CVE-2018-2475

CVSS v3.1

8.5

High

VectorAV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Gardener versions prior to 0.12.4
Description The issue arises from missing network isolation in the Gardener architecture, allowing a shoot's apiserver to access services or endpoints in the private network of its corresponding seed cluster. When combined with other minor Kubernetes security issues, this could theoretically lead to the compromise of other shoot or seed clusters within the Gardener context. The impact of potential exploitation is considered high.
Recommendations For versions prior to 0.12.4, update to Gardener release 0.12.4 to resolve the issue. As a temporary workaround, consider restricting access to the private network of seed clusters to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2018-2475

Affected Products

Gardener