VDB
Sign up
MEDIUM5.8

GHSA-35c7-w35f-xwgh

Kube-proxy may unintentionally forward traffic

Quick fix

GHSA-35c7-w35f-xwgh — k8s.io/kubernetes: upgrade to the fixed version with the command below.

go get k8s.io/kubernetes@v1.21.0

Details

Kube-proxy on Windows can unintentionally forward traffic to local processes listening on the same port (`spec.ports[*].port`) as a LoadBalancer Service when the LoadBalancer controller does not set the `status.loadBalancer.ingress[].ip` field. Clusters where the LoadBalancer controller sets the `status.loadBalancer.ingress[].ip` field are unaffected.

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/k8s.io/kubernetes
Introduced in: 0Fixed in: 1.21.0
Fixgo get k8s.io/kubernetes@v1.21.0

References