Skip to main content

Externally Controlled Reference to a Resource in Another Sphere

CVE-2021-25740

Severity Low
Score 3.1/10

Summary

A security issue was discovered in all versions with Kubernetes that could enable users to send network traffic to locations they would otherwise not have access to via a confused deputy attack.

  • HIGH
  • NETWORK
  • NONE
  • UNCHANGED
  • NONE
  • LOW
  • LOW
  • NONE

CWE-610 - Externally Controlled Reference to a Resource in Another Sphere

The product uses an externally controlled name or reference that resolves to a resource that is outside of the intended control sphere.

Advisory Timeline

  • Published