CVE Vulnerabilities

CVE-2021-25736

Published: Oct 30, 2023 | Modified: Dec 21, 2023
CVSS 3.x
6.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
5.8 MODERATE
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:N
Ubuntu
MEDIUM

Kube-proxy on Windows can unintentionally forward traffic to local processes listening on the same port (“spec.ports[*].port”) as a LoadBalancer Service when the LoadBalancer controller does not set the “status.loadBalancer.ingress[].ip” field. Clusters where the LoadBalancer controller sets the “status.loadBalancer.ingress[].ip” field are unaffected.

Affected Software

Name Vendor Start Version End Version
Kubernetes Kubernetes 1.18.0 (including) 1.18.18 (excluding)
Kubernetes Kubernetes 1.19.0 (including) 1.19.10 (excluding)
Kubernetes Kubernetes 1.20.0 (including) 1.20.6 (excluding)
Red Hat OpenShift Container Platform 4.7 RedHat openshift4-wincw/windows-machine-config-operator-bundle:v2.0.1-8 *
Red Hat OpenShift Container Platform 4.7 RedHat openshift4-wincw/windows-machine-config-rhel8-operator:2.0.1-6 *

References