Externally Controlled Reference to a Resource in Another Sphere
CVE-2021-25740
Summary
A security issue was discovered in all versions with Kubernetes that could enable users to send network traffic to locations they would otherwise not have access to via a confused deputy attack.
- HIGH
- NETWORK
- NONE
- UNCHANGED
- NONE
- LOW
- LOW
- NONE
CWE-610 - Externally Controlled Reference to a Resource in Another Sphere
The product uses an externally controlled name or reference that resolves to a resource that is outside of the intended control sphere.
References
Advisory Timeline
- Published