CVE-2021-25740: Holes in EndpointSlice Validation Enable Host Network Hijack
A security issue was discovered with Kubernetes that could enable users to send network traffic to locations they would otherwise not have access to via a confused deputy attack.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-25740?
CVE-2021-25740 is a security issue discovered in Kubernetes that allows users to send network traffic to unauthorized locations through a confused deputy attack.
How does CVE-2021-25740 affect Kubernetes?
CVE-2021-25740 affects Kubernetes by enabling users to send network traffic to locations they should not have access to.
What is the severity of CVE-2021-25740?
The severity of CVE-2021-25740 is low, with a severity value of 3.1.
What is a confused deputy attack?
A confused deputy attack refers to a situation where an authorized entity is manipulated by an attacker to perform actions on their behalf, potentially granting unintended privileges.
How can I fix CVE-2021-25740 in Kubernetes?
To fix CVE-2021-25740 in Kubernetes, it is recommended to apply the relevant security patches and updates provided by Kubernetes.