icon

We found results for “”

CVE-2021-25736

Good to know:

icon

Date: January 22, 2021

A flaw was found in the Windows kube-proxy component in Kubernetes before 1.18.18, 1.19.10, 1.20.6, 1.21.0. In a cloud environment that does not set the “.status.loadBalancer.ingress.ip” field in the LoadBalancer service status configuration (for example in AWS) the packets can be misrouted and reach an unintended destination.

Language: Go

Severity Score

Severity Score

Top Fix

icon

Upgrade Version

Upgrade to version kubernetes - 1.18.18, 1.19.10, 1.20.6, 1.21.0

Learn More

CVSS v3.1

Base Score:
Attack Vector (AV): NETWORK
Attack Complexity (AC): HIGH
Privileges Required (PR): HIGH
User Interaction (UI): NONE
Scope (S): CHANGED
Confidentiality (C): HIGH
Integrity (I): NONE
Availability (A): NONE

Do you need more information?

Contact Us