A security issue was discovered in Kubernetes where actors that control the responses of MutatingWebhookConfiguration or ValidatingWebhookConfiguration requests are able to redirect kube-apiserver requests to private networks of the apiserver. If that user can view kube-apiserver logs when the log level is set to 10, they can view the redirected responses and headers in the logs.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| k8s.io/kubernetes(Go) | 0 | N/A | N/A |
CVSS Metrics