CVE-2021-25735
medium
CVSS v3
—
CVSS v2
—
VIR risk
5.5
Description
A security issue was discovered in kube-apiserver that could allow node updates to bypass a Validating Admission Webhook. Clusters are only affected by this vulnerability if they run a Validating Admission Webhook for Nodes that denies admission based at least partially on the old state of the Node object. Validating Admission Webhook does not observe some previous fields.
Predictions
Exploit likelihood
30%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2021-25735
Vendor advisory: suse — https://www.suse.com/security/cve/CVE-2021-25735.html
OS impact
| OS | Version | Status | Fixed in |
|---|---|---|---|
| arch | fixed | 1.21.0-1 | |
| sles | affected | | |
| debian | bookworm | fixed | 1.20.5+really1.20.2-1 |
| debian | bullseye | fixed | 1.20.5+really1.20.2-1 |
| debian | forky | fixed | 1.20.5+really1.20.2-1 |
| debian | sid | fixed | 1.20.5+really1.20.2-1 |
| debian | trixie | fixed | 1.20.5+really1.20.2-1 |
Package impact
| Ecosystem | Package | Vulnerable | Fixed |
|---|---|---|---|
| Go | k8s.io/kubernetes | >=1.20.0,<1.20.6 | 1.20.6 |
| Go | k8s.io/kubernetes | >=1.19.0,<1.19.10 | 1.19.10 |
| Go | k8s.io/kubernetes | <1.18.18 | 1.18.18 |
References
- https://www.suse.com/security/cve/CVE-2021-25735.html
- https://nvd.nist.gov/vuln/detail/CVE-2021-25735
- https://github.com/kubernetes/kubernetes/issues/100096
- https://github.com/kubernetes/kubernetes/pull/99946
- https://github.com/kubernetes/kubernetes/commit/00e81db174ef7aca497be5f42d87e46d14df2a90
- https://bugzilla.redhat.com/show_bug.cgi?id=1937562
- https://github.com/kubernetes/kubernetes
- https://groups.google.com/g/kubernetes-security-announce/c/FKAGqT4jx9Y
- https://pkg.go.dev/k8s.io/kubernetes@v1.23.5/cmd/kube-apiserver
- https://sysdig.com/blog/cve-2021-25735-kubernetes-admission-bypass
- https://github.com/advisories/GHSA-g42g-737j-qx6j
- https://security-tracker.debian.org/tracker/CVE-2021-25735
Verify integrity in audit chain (admin only). AS-IS.