A security issue was discovered in kube-apiserver that could allow node updates to bypass a Validating Admission Webhook. Clusters are only affected by this vulnerability if they run a Validating Admission Webhook for Nodes that denies admission based at least partially on the old state of the Node object. Validating Admission Webhook does not observe some previous fields.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| k8s.io/kubernetes(Go) | 1.20.0 | 1.20.6 | N/A |
| k8s.io/kubernetes(Go) | 1.19.0 | 1.19.10 | N/A |
| k8s.io/kubernetes(Go) | 0 | 1.18.18 | N/A |
CVSS Metrics