HIGH7.7
GHSA-xx8c-m748-xr4j
Access Restriction Bypass in kubernetes
Quick fix
GHSA-xx8c-m748-xr4j — github.com/kubernetes/kubernetes: upgrade to the fixed version with the command below.
go get github.com/kubernetes/kubernetes@v1.2.0-alpha.6Details
The API server in Kubernetes does not properly check admission control, which allows remote authenticated users to access additional resources via a crafted patched object.
### Specific Go Packages Affected github.com/kubernetes/kubernetes/pkg/apiserver
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/github.com/kubernetes/kubernetes
Introduced in:
0Fixed in: 1.2.0-alpha.6Fix
go get github.com/kubernetes/kubernetes@v1.2.0-alpha.6References
- https://nvd.nist.gov/vuln/detail/CVE-2016-1905[ADVISORY]
- https://github.com/kubernetes/kubernetes/issues/19479[WEB]
- https://github.com/kubernetes/kubernetes/commit/9e6912384a5bc714f2a780b870944a8cee264a22[WEB]
- https://access.redhat.com/errata/RHSA-2016:0070[WEB]
- https://access.redhat.com/errata/RHSA-2016:0351[WEB]
- https://access.redhat.com/security/cve/CVE-2016-1905[WEB]
- https://bugzilla.redhat.com/show_bug.cgi?id=1297910[WEB]