VDB
Sign up
MEDIUM6.7

GHSA-4x4m-3c2p-qppc

Kubernetes Nodes can delete themselves by adding an OwnerReference

Quick fix

GHSA-4x4m-3c2p-qppc — k8s.io/kubernetes: upgrade to the fixed version with the command below.

go get k8s.io/kubernetes@v1.31.12

Details

A vulnerability exists in the NodeRestriction admission controller in Kubernetes clusters where node users can delete their corresponding node object by patching themselves with an OwnerReference to a cluster-scoped resource. If the OwnerReference resource does not exist or is subsequently deleted, the given node object will be deleted via garbage collection.

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/k8s.io/kubernetes
Introduced in: 0Fixed in: 1.31.12
Fixgo get k8s.io/kubernetes@v1.31.12
Go/k8s.io/kubernetes
Introduced in: 1.32.0-alpha.0Fixed in: 1.32.8
Fixgo get k8s.io/kubernetes@v1.32.8
Go/k8s.io/kubernetes
Introduced in: 1.33.0-alpha.0Fixed in: 1.33.4
Fixgo get k8s.io/kubernetes@v1.33.4

References