Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [day] [month] [year] [list]
Date: Wed, 14 Apr 2021 09:06:02 -0700
From: Tim Allclair <>
Subject: [kubernetes] CVE-2021-25735: Validating Admission Webhook does not
 observe some previous fields

A security issue was discovered in kube-apiserver that could allow node
updates to bypass a Validating Admission Webhook. You are only affected by
this vulnerability if you run a Validating Admission Webhook for Nodes that
denies admission based at least partially on the old state of the Node

This issue has been rated Medium (
and assigned CVE-2021-25735.

Note: This only impacts validating admission plugins that rely on old
values in certain fields, and does not impact calls from kubelets that go
through the built-in NodeRestriction admission plugin.
Affected Versions


   kube-apiserver v1.20.0 - v1.20.5

   kube-apiserver v1.19.0 - v1.19.9

   kube-apiserver <= v1.18.17

Fixed Versions

This issue is fixed in the following versions:


   kube-apiserver v1.21.0

   kube-apiserver v1.20.6

   kube-apiserver v1.19.10

   kube-apiserver v1.18.18


If you find evidence that this vulnerability has been exploited, please
Additional Details

See Kubernetes Issue #100096
<> for more details.

This vulnerability was reported by Rogerio Bastos & Ari Lima from RedHat

Thank You,

Tim Allclair on behalf of the Kubernetes Product Security Committee

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.