CVE-2021-25740

A security issue was discovered with Kubernetes that could enable users to send network traffic to locations they would otherwise not have access to via a confused deputy attack.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:kubernetes:kubernetes:-:*:*:*:*:*:*:*

History

06 Nov 2021, 02:49

Type Values Removed Values Added
References (CONFIRM) https://security.netapp.com/advisory/ntap-20211014-0001/ - (CONFIRM) https://security.netapp.com/advisory/ntap-20211014-0001/ - Third Party Advisory

14 Oct 2021, 09:15

Type Values Removed Values Added
References
  • (CONFIRM) https://security.netapp.com/advisory/ntap-20211014-0001/ -

01 Oct 2021, 13:19

Type Values Removed Values Added
References (MLIST) https://groups.google.com/g/kubernetes-security-announce/c/WYE9ptrhSLE - (MLIST) https://groups.google.com/g/kubernetes-security-announce/c/WYE9ptrhSLE - Mailing List, Mitigation, Third Party Advisory
References (CONFIRM) https://github.com/kubernetes/kubernetes/issues/103675 - (CONFIRM) https://github.com/kubernetes/kubernetes/issues/103675 - Mitigation, Third Party Advisory
CWE CWE-610
CPE cpe:2.3:a:kubernetes:kubernetes:-:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : 3.5
v3 : 3.1

20 Sep 2021, 17:21

Type Values Removed Values Added
New CVE

Information

Published : 2021-09-20 17:15

Updated : 2023-12-10 14:09


NVD link : CVE-2021-25740

Mitre link : CVE-2021-25740

CVE.ORG link : CVE-2021-25740


JSON object : View

Products Affected

kubernetes

  • kubernetes
CWE
CWE-610

Externally Controlled Reference to a Resource in Another Sphere

CWE-441

Unintended Proxy or Intermediary ('Confused Deputy')