PT-2021-3738 · Red Hat · Red Hat Openshift Container Platform

Cj Cullen

+1

·

Published

2021-07-15

·

Updated

2026-05-22

·

CVE-2021-25740

CVSS v2.0

3.5

Low

VectorAV:N/AC:M/Au:S/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Kubernetes (affected versions not specified)
Description A security issue exists in Kubernetes that could allow users to send network traffic to locations they would not normally have access to. This is due to a confused deputy attack. The issue involves permissions related to Endpoint and EndpointSlice resources, potentially enabling cross-Namespace forwarding. A confused deputy attack occurs when a program with certain privileges is tricked into performing actions on behalf of another program, potentially granting unauthorized access or causing unintended consequences.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Incorrect Authorization

Weakness Enumeration

Related Identifiers

BDU:2021-03991
CVE-2021-25740
GHSA-VW47-MR44-3JF9
OESA-2022-2139

Affected Products

Red Hat Openshift Container Platform