First published: Wed Jul 14 2021(Updated: )
A security issue was discovered with Kubernetes that could enable users to send network traffic to locations they would otherwise not have access to via a confused deputy attack.
Credit: jordan@liggitt.net
Affected Software | Affected Version | How to fix |
---|---|---|
Kubernetes Dashboard |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-25740 is a security issue discovered in Kubernetes that allows users to send network traffic to unauthorized locations through a confused deputy attack.
CVE-2021-25740 affects Kubernetes by enabling users to send network traffic to locations they should not have access to.
The severity of CVE-2021-25740 is low, with a severity value of 3.1.
A confused deputy attack refers to a situation where an authorized entity is manipulated by an attacker to perform actions on their behalf, potentially granting unintended privileges.
To fix CVE-2021-25740 in Kubernetes, it is recommended to apply the relevant security patches and updates provided by Kubernetes.