Sploitus

CVE-2021-25735

2 known exploits for CVE-2021-25735

A security issue was discovered in kube-apiserver that could allow node updates to bypass a Validating Admission Webhook. Clusters are only affected by this vulnerability if they run a Validating Admission Webhook for Nodes that denies admission based at least partially on the old state of the Node object. Validating Admission Webhook does not observe some previous fields.

Kubernetes
< 1.18.18, 1.19.10, 1.20.6
CVSS 3.1
6.5 MEDIUM
EPSS
5.5% (92th percentile)
Weakness
CWE-372
NVD status
Modified
Published
2021-09-06
CVE-2021-25735 at NVD
Authoritative description, scoring and affected products

2 known exploits for CVE-2021-25735

Proof-of-concept code and exploit modules indexed by Sploitus