Back

HIGH

Node address isn't always verified when proxying

Published Mar 1, 2023

Description

Users may have access to secure endpoints in the control plane network. Kubernetes clusters are only affected if an untrusted user can modify Node objects and send proxy requests to them. Kubernetes supports node proxying, which allows clients of kube-apiserver to access endpoints of a Kubelet to establish connections to Pods, retrieve container logs, and more. While Kubernetes already validates the proxying address for Nodes, a bug in kube-apiserver made it possible to bypass this validation. Bypassing this validation could allow authenticated requests destined for Nodes to to the API server's private network.

Affected products

Remediation

Vendor solution

Configuring an egress proxy for egress to the cluster network can mitigate this vulnerability

Red Hat statement

Kubernetes clusters are only affected if an untrusted user can modify Node objects and send requests proxying through them. The "openshift" component of Red Hat OpenShift Container Platform 4 was fixed in RHBA-2023:0452 and as such is marked not affected.

References (9)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner kubernetes
Published Mar 1, 2023
Updated Mar 7, 2025
Reserved Sep 23, 2022
CISA Vulnrichment
Updated Mar 7, 2025
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Nov 10, 2022
ENISA EUVD
Assigner kubernetes
Published Mar 1, 2023
Updated Mar 7, 2025
Exploited since n/a
EUVD-2023-1049 GHSA-JH36-Q97C-9928