PT-2021-6571 · Unknown · Kubernetes

Qiqi Xu

·

Published

2021-09-01

·

Updated

2026-06-01

·

CVE-2020-8561

CVSS v3.1

4.1

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:C/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Kubernetes (affected versions not specified)
Description A security issue was discovered in Kubernetes where actors that control the responses of MutatingWebhookConfiguration or ValidatingWebhookConfiguration requests are able to redirect kube-apiserver requests to private networks of the apiserver. If that user can view kube-apiserver logs when the log level is set to 10, they can view the redirected responses and headers in the logs. The issue is related to errors in processing hyperlinks, which can allow a remote attacker to access confidential data. Additionally, the kube-apiserver, scheduler, controller-manager, and kubelet have profiling enabled by default, and access to this information can be obtained by accessing the /debug/pprof/profile endpoint, although necessary RBAC rights are required for kube-apiserver, kube-controller-manager, and kube-scheduler.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Weakness Enumeration

Related Identifiers

BDU:2022-01837
CVE-2020-8561
GHSA-74J8-88MM-7496

Affected Products

Kubernetes