Bug 813645 (CVE-2020-8561) - sys-cluster/kube-apiserver: webhook redirect vulnerability
Summary: sys-cluster/kube-apiserver: webhook redirect vulnerability
Alias: CVE-2020-8561
Reported: 2021-09-18 13:37 UTC by John Helmert III
Modified: 2021-09-18 13:38 UTC (History)
John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2021-09-18 13:37:57 UTC
"A security issue was discovered in Kubernetes where actors that control the responses of MutatingWebhookConfiguration or ValidatingWebhookConfiguration requests are able to redirect kube-apiserver requests to private networks of the apiserver. If that user can view kube-apiserver logs when the log level is set to 10, they can view the redirected responses and headers in the logs."

No upstream fix.