Skip to content

CVE upgrade requirement k8s.io >=1.18.19 #74

@jeffbanks

Description

@jeffbanks

Issue

Per CVE-2021-25737, upgrade to at least 1.18.19 is recommended.

Moderate severity issue

A security issue was discovered in Kubernetes where a user may be able to redirect pod traffic to private networks on a Node. Kubernetes already prevents creation of Endpoint IPs in the localhost or link-local range, but the same validation was not performed on EndpointSlice IPs.

**Fix:
Upgrading 1.18.19

┆Issue is synchronized with this Jira Task by Unito
┆Issue Number: K8SSAND-941
┆Priority: Medium

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't workingneeds-triagezh:IceboxIssues in the ZenHub pipeline 'Icebox'

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions