CVE-2018-2475: High severity gardener vulnerability
Following the Gardener architecture, the Kubernetes apiserver of a Gardener managed shoot cluster resides in the corresponding seed cluster. Due to missing network isolation a shoot's apiserver can access services/endpoints in the private network of its corresponding seed cluster. Combined with other minor Kubernetes security issues, the missing network isolation theoretically can lead to compromise other shoot or seed clusters in the "Gardener" context. The issue is rated high due to the high impact of a potential exploitation in "Gardener" context. This was fixed in Gardener release 0.12.4.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-2475?
CVE-2018-2475 has a medium severity level due to potential unauthorized access to services in the seed cluster.
How do I fix CVE-2018-2475?
To mitigate CVE-2018-2475, ensure proper network isolation is implemented between the shoot cluster and the seed cluster.
What systems are affected by CVE-2018-2475?
CVE-2018-2475 affects Gardener versions up to 0.12.4.
What can happen if CVE-2018-2475 is exploited?
Exploitation of CVE-2018-2475 can allow a shoot cluster's apiserver to access sensitive services in its seed cluster's private network.
Who is responsible for addressing CVE-2018-2475?
Users and administrators of Gardener-managed clusters should take action to address CVE-2018-2475 and ensure network isolation.