Access Restriction Bypass Affecting k8s.io/kubernetes/plugin/pkg/auth/authorizer/rbac/bootstrappolicy package, versions *


Severity

Recommended
0.0
low
0
10

CVSS assessment made by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.08% (35th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Access Restriction Bypass vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-GOLANG-K8SIOKUBERNETESPLUGINPKGAUTHAUTHORIZERRBACBOOTSTRAPPOLICY-1318920
  • published15 Jul 2021
  • disclosed15 Jul 2021
  • creditUnknown

Introduced: 15 Jul 2021

CVE-2021-25740  (opens in a new tab)
CWE-284  (opens in a new tab)

How to fix?

There is no fixed version for k8s.io/kubernetes/plugin/pkg/auth/authorizer/rbac/bootstrappolicy.

Overview

k8s.io/kubernetes/plugin/pkg/auth/authorizer/rbac/bootstrappolicy is a package rbac that implements the authorizer.Authorizer interface using roles base access control.

Affected versions of this package are vulnerable to Access Restriction Bypass. Endpoint & EndpointSlice permissions allow cross-Namespace forwarding. If a potential attacker can create or edit Endpoints or EndpointSlices in the Kubernetes API, they can potentially direct a LoadBalancer or Ingress implementation to expose backend IPs the attacker should not have access to.

CVSS Scores

version 3.1