PT-2021-6571 · Unknown · Kubernetes
Qiqi Xu
·
Published
2021-09-01
·
Updated
2026-06-01
·
CVE-2020-8561
CVSS v3.1
4.1
Medium
| Vector | AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Kubernetes (affected versions not specified)
Description
A security issue was discovered in Kubernetes where actors that control the responses of
MutatingWebhookConfiguration or ValidatingWebhookConfiguration requests are able to redirect kube-apiserver requests to private networks of the apiserver. If that user can view kube-apiserver logs when the log level is set to 10, they can view the redirected responses and headers in the logs. The issue is related to errors in processing hyperlinks, which can allow a remote attacker to access confidential data. Additionally, the kube-apiserver, scheduler, controller-manager, and kubelet have profiling enabled by default, and access to this information can be obtained by accessing the /debug/pprof/profile endpoint, although necessary RBAC rights are required for kube-apiserver, kube-controller-manager, and kube-scheduler.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Kubernetes