GHSA-j9wf-vvm6-4r9wMediumCVSS 5.0

Unverified Ownership in Kubernetes

Published
February 8, 2022
Last Modified
June 9, 2026

🔗 CVE IDs covered (1)

📋 Description

Kubernetes API server in all versions allow an attacker who is able to create a ClusterIP service and set the spec.externalIPs field, to intercept traffic to that IP address. Additionally, an attacker who is able to patch the status (which is considered a privileged operation and should not typically be granted to users) of a LoadBalancer service can set the status.loadBalancer.ingress.ip to similar effect.

🎯 Affected products1

  • go/k8s.io/kubernetes:<= 1.22.0

🔗 References (17)