Security Advisory

CVE-2021-25735

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2021-09-06 11:32:00
Last updated 2024-09-16 23:40:25
Assigner kubernetes
State PUBLISHED

Description

A security issue was discovered in kube-apiserver that could allow node updates to bypass a Validating Admission Webhook. Clusters are only affected by this vulnerability if they run a Validating Admission Webhook for Nodes that denies admission based at least partially on the old state of the Node object. Validating Admission Webhook does not observe some previous fields.