#VU56245 Input validation error in Kubernetes - CVE-2021-25735
Published: September 1, 2021 / Updated: September 12, 2021
Kubernetes
Kubernetes
Description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to insufficient validation of user-supplied input in kube-apiserver that could allow Node updates to bypass a Validating Admission Webhook. An authenticated user could exploit this by modifying Node properties to values that should have been prevented by registered admission webhooks.