Unverified Ownership in Kubernetes
Moderate severity
GitHub Reviewed
Published
Feb 8, 2022
to the GitHub Advisory Database
•
Updated Jan 29, 2023
Description
Published by the National Vulnerability Database
Jan 21, 2021
Reviewed
May 12, 2021
Published to the GitHub Advisory Database
Feb 8, 2022
Last updated
Jan 29, 2023
Kubernetes API server in all versions allow an attacker who is able to create a ClusterIP service and set the spec.externalIPs field, to intercept traffic to that IP address. Additionally, an attacker who is able to patch the status (which is considered a privileged operation and should not typically be granted to users) of a LoadBalancer service can set the status.loadBalancer.ingress.ip to similar effect.
References