Summary
Kube-proxy on Windows can unintentionally forward traffic destined for a LoadBalancer service to a local process listening on the same port when the ingress IP field is not set, potentially exposing confidential data; exploitation requires network access to a Windows-based Kubernetes cluster with a LoadBalancer service and specific ingress IP conditions.
Why Planned Fix?
2/6Exploitation Details
Confidentiality breach by forwarding LoadBalancer traffic to a local process, enabling potential exposure of sensitive data
Affected Software
| Product | Affected Versions |
|---|---|
| kube-proxy (Windows) | Kubernetes 1.18.0-1.18.17; 1.19.0-1.19.9; 1.20.0-1.20.5 |
Kubernetes component that runs on each node to manage network routing for Services, including LoadBalancer type services.
Affected Componentkube-proxy on Windows handling LoadBalancer service traffic
kube-proxy on Windows handling LoadBalancer service traffic
Affected Endpoints(3)https://github.com/kubernetes/kubernetes/pull/99958, https://groups.google.com/g/kubernetes-security-announce/c/lIoOPObO51Q/m/O15LOazPAgAJ…
Not available
Not available
Not available
Probability of exploitation in the next 30 days
Worse than 31% of all CVEs
No known threat actors
NVD Data
Description Summary
CVSS Base Score
CVSS Vector (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N)
Affected Software (CPE) (4)
- •cpe:2.3:a:kubernetes:kubernetes:1.18.0:*:*:*:*:*:*:*
- •cpe:2.3:a:kubernetes:kubernetes:1.19.0:*:*:*:*:*:*:*
- •cpe:2.3:a:kubernetes:kubernetes:1.20.0:*:*:*:*:*:*:*
- •cpe:2.3:o:microsoft:windows:*:*:*:*:*:*:*:*
Sources
| Source | Article |
|---|---|
| nvd.nist.gov | https://nvd.nist.gov/vuln/detail/CVE-2021-25736 |
| github.com | https://github.com/kubernetes/kubernetes/pull/99958 |
| groups.google.com | https://groups.google.com/g/kubernetes-security-announce/c/lIoOPObO51Q/m/O15LOazPAgAJ |
| security.netapp.com | https://security.netapp.com/advisory/ntap-20231221-0003/ |
| www.ibm.com | https://www.ibm.com/support/pages/node/7244082 |
| www.sentinelone.com | https://www.sentinelone.com/vulnerability-database/cve-2021-25736/ |
| www.wiz.io | https://www.wiz.io/vulnerability-database/cve/cve-2021-25736 |
| osv.dev | https://osv.dev/vulnerability/CVE-2021-25736 |
Priority History
Initial analysis