CVE-2021-25735 Kubernetes 准入機制繞過漏洞

From PwnWiki
Revision as of 10:30, 22 May 2021 by Pwnwiki (talk | contribs) (Created page with "==影響版本== <pre> kube-apiserver v1.20.0 - v1.20.5 kube-apiserver v1.19.0 - v1.19.9 kube-apiserver <= v1.18.17 </pre> ==漏洞利用== 通過執行組合操作將changeA...")
(diff) ← Older revision | Latest revision (diff) | Newer revision → (diff)

影響版本

kube-apiserver v1.20.0 - v1.20.5
kube-apiserver v1.19.0 - v1.19.9
kube-apiserver <= v1.18.17

漏洞利用

通過執行組合操作將changeAllowed標籤更改為true並添加一個新標籤,觸發該漏洞,新的值已被准入控制器覆蓋:

 labels:  
    test: test  
    changeAllowed: "true"