Externally Controlled Reference to a Resource in Another Sphere in Kubernetes - CVE-2020-8561
Published: September 18, 2024
Kubernetes
Kubernetes
Description
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to excessive data output by the application. A remote attacker that control the responses of MutatingWebhookConfiguration or ValidatingWebhookConfiguration requests is able to redirect kube-apiserver requests to private networks of the apiserver.