Back

MEDIUM

Webhook redirect in kube-apiserver

Published Sep 20, 2021

Description

A security issue was discovered in Kubernetes where actors that control the responses of MutatingWebhookConfiguration or ValidatingWebhookConfiguration requests are able to redirect kube-apiserver requests to private networks of the apiserver. If that user can view kube-apiserver logs when the log level is set to 10, they can view the redirected responses and headers in the logs.

Affected products

Remediation

Red Hat statement

OpenShift Container Platform 4 does not support logging levels higher than 8 in the kube-apiserver (via the 'TraceAll' option), thereby making it not affected by this vulnerability. https://docs.openshift.com/container-platform/4.8/rest_api/operator_apis/kubeapiserver-operator-openshift-io-v1.html https://github.com/openshift/api/blob/release-4.8/operator/v1/types.go#L103

References (10)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner kubernetes
Published Sep 20, 2021
Updated Jun 1, 2026
Reserved Feb 3, 2020
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Sep 15, 2021
ENISA EUVD
Assigner kubernetes
Published Sep 20, 2021
Updated Jun 1, 2026
Exploited since n/a
EUVD-2021-2002 GHSA-74J8-88MM-7496