A security issue was discovered in kube-apiserver that could allow node updates to bypass a Validating Admission Webhook. You are only affected by this vulnerability if you run a Validating Admission Webhook for Nodes that denies admission based at least partially on the old state of the Node object.
Note: This only impacts validating admission plugins that rely on old values in certain fields, and does not impact calls from kubelets that go through the built-in NodeRestriction admission plugin.
This release also addresses CVE-2021-3121 (see also bug 765046).
Fixes in 1.20.6, 1.19.10, and 1.18.18. Please bump.
All versions older than the ones listed in this bug have been removed
from the tree.
Package list is empty or all packages have requested keywords.