Debian Kubernetes vulnerabilities
49 known vulnerabilities affecting debian/kubernetes.
Total CVEs
49
CISA KEV
0
Public exploits
3
Exploited in wild
1
Severity breakdown
CRITICAL2HIGH11MEDIUM26LOW10
Vulnerabilities
Page 2 of 3
CVE-2021-25735P3MEDIUMCVSS 6.5fixed in kubernetes 1.20.5+really1.20.2-1 (bookworm)2021
CVE-2021-25735 [MEDIUM] CVE-2021-25735: kubernetes - A security issue was discovered in kube-apiserver that could allow node updates ...
A security issue was discovered in kube-apiserver that could allow node updates to bypass a Validating Admission Webhook. Clusters are only affected by this vulnerability if they run a Validating Admission Webhook for Nodes that denies admission based at least partially on the old state of the Node object. Validating Admission Webhook does not observe some prev
debian
CVE-2019-11250P3MEDIUMCVSS 6.5fixed in kubernetes 1.17.4-1 (bookworm)2019
CVE-2019-11250 [MEDIUM] CVE-2019-11250: kubernetes - The Kubernetes client-go library logs request headers at verbosity levels of 7 o...
The Kubernetes client-go library logs request headers at verbosity levels of 7 or higher. This can disclose credentials to unauthorized users via logs or command output. Kubernetes components (such as kube-apiserver) prior to v1.16.0, which make use of basic or bearer token authentication, and run at high verbosity levels, are affected.
Scope: local
bookworm: r
debian
CVE-2019-11254P3MEDIUMCVSS 6.5fixed in kubernetes 1.17.4-1 (bookworm)2019
CVE-2019-11254 [MEDIUM] CVE-2019-11254: kubernetes - The Kubernetes API Server component in versions 1.1-1.14, and versions prior to ...
The Kubernetes API Server component in versions 1.1-1.14, and versions prior to 1.15.10, 1.16.7 and 1.17.3 allows an authorized user who sends malicious YAML payloads to cause the kube-apiserver to consume excessive CPU cycles while parsing YAML.
Scope: local
bookworm: resolved (fixed in 1.17.4-1)
bullseye: resolved (fixed in 1.17.4-1)
forky: resolved (fixed in
debian
CVE-2022-3162P3MEDIUMCVSS 6.5fixed in kubernetes 1.20.5+really1.20.2-1 (bookworm)2022
CVE-2022-3162 [MEDIUM] CVE-2022-3162: kubernetes - Users authorized to list or watch one type of namespaced custom resource cluster...
Users authorized to list or watch one type of namespaced custom resource cluster-wide can read custom resources of a different type in the same API group without authorization. Clusters are impacted by this vulnerability if all of the following are true: 1. There are 2+ CustomResourceDefinitions sharing the same API group 2. Users have cluster-wide list or watch
debian
CVE-2020-8559P3MEDIUMCVSS 6.4fixed in kubernetes 1.18.5-1 (bookworm)2020
CVE-2020-8559 [MEDIUM] CVE-2020-8559: kubernetes - The Kubernetes kube-apiserver in versions v1.6-v1.15, and versions prior to v1.1...
The Kubernetes kube-apiserver in versions v1.6-v1.15, and versions prior to v1.16.13, v1.17.9 and v1.18.6 are vulnerable to an unvalidated redirect on proxied upgrade requests that could allow an attacker to escalate privileges from a node compromise to a full cluster compromise.
Scope: local
bookworm: resolved (fixed in 1.18.5-1)
bullseye: resolved (fixed in 1.1
debian
CVE-2023-2727P3MEDIUMCVSS 6.5fixed in kubernetes 1.20.5+really1.20.2-1 (bookworm)2023
CVE-2023-2727 [MEDIUM] CVE-2023-2727: kubernetes - Users may be able to launch containers using images that are restricted by Image...
Users may be able to launch containers using images that are restricted by ImagePolicyWebhook when using ephemeral containers. Kubernetes clusters are only affected if the ImagePolicyWebhook admission plugin is used together with ephemeral containers.
Scope: local
bookworm: resolved (fixed in 1.20.5+really1.20.2-1)
bullseye: resolved (fixed in 1.20.5+really1.20.2
debian
CVE-2025-5187P3MEDIUMCVSS 6.7fixed in kubernetes 1.20.5+really1.20.2-1 (bookworm)2025
CVE-2025-5187 [MEDIUM] CVE-2025-5187: kubernetes - A vulnerability exists in the NodeRestriction admission controller in Kubernetes...
A vulnerability exists in the NodeRestriction admission controller in Kubernetes clusters where node users can delete their corresponding node object by patching themselves with an OwnerReference to a cluster-scoped resource. If the OwnerReference resource does not exist or is subsequently deleted, the given node object will be deleted via garbage collection.
Sco
debian
CVE-2025-13281P3MEDIUMCVSS 5.8fixed in kubernetes 1.20.5+really1.20.2-1 (bookworm)2025
CVE-2025-13281 [MEDIUM] CVE-2025-13281: kubernetes - A half-blind Server Side Request Forgery (SSRF) vulnerability exists in kube-con...
A half-blind Server Side Request Forgery (SSRF) vulnerability exists in kube-controller-manager when using the in-tree Portworx StorageClass. This vulnerability allows authorized users to leak arbitrary information from unprotected endpoints in the control plane’s host network (including link-local or loopback services).
Scope: local
bookworm: resolved (fixed i
debian
CVE-2025-1767P4MEDIUMCVSS 6.5fixed in kubernetes 1.20.5+really1.20.2-1 (bookworm)2025
CVE-2025-1767 [MEDIUM] CVE-2025-1767: kubernetes - This CVE only affects Kubernetes clusters that utilize the in-tree gitRepo volum...
This CVE only affects Kubernetes clusters that utilize the in-tree gitRepo volume to clone git repositories from other pods within the same node. Since the in-tree gitRepo volume feature has been deprecated and will not receive security updates upstream, any cluster still using this feature remains vulnerable.
Scope: local
bookworm: resolved (fixed in 1.20.5+real
debian
CVE-2019-11252P4MEDIUMCVSS 5.9fixed in kubernetes 1.18.0-1 (bookworm)2019
CVE-2019-11252 [MEDIUM] CVE-2019-11252: kubernetes - The Kubernetes kube-controller-manager in versions v1.0-v1.17 is vulnerable to a...
The Kubernetes kube-controller-manager in versions v1.0-v1.17 is vulnerable to a credential leakage via error messages in mount failure logs and events for AzureFile and CephFS volumes.
Scope: local
bookworm: resolved (fixed in 1.18.0-1)
bullseye: resolved (fixed in 1.18.0-1)
forky: resolved (fixed in 1.18.0-1)
sid: resolved (fixed in 1.18.0-1)
trixie: resolved
debian
CVE-2017-1002102P4HIGHCVSS 7.1fixed in kubernetes 1.7.16+dfsg-1 (bookworm)2017
CVE-2017-1002102 [HIGH] CVE-2017-1002102: kubernetes - In Kubernetes versions 1.3.x, 1.4.x, 1.5.x, 1.6.x and prior to versions 1.7.14, ...
In Kubernetes versions 1.3.x, 1.4.x, 1.5.x, 1.6.x and prior to versions 1.7.14, 1.8.9 and 1.9.4 containers using a secret, configMap, projected or downwardAPI volume can trigger deletion of arbitrary files/directories from the nodes where they are running.
Scope: local
bookworm: resolved (fixed in 1.7.16+dfsg-1)
bullseye: resolved (fixed in 1.7.16+dfsg-1)
for
debian
CVE-2018-1002100P4MEDIUMCVSS 4.2fixed in kubernetes 1.17.4-1 (bookworm)2018
CVE-2018-1002100 [MEDIUM] CVE-2018-1002100: kubernetes - In Kubernetes versions 1.5.x, 1.6.x, 1.7.x, 1.8.x, and prior to version 1.9.6, t...
In Kubernetes versions 1.5.x, 1.6.x, 1.7.x, 1.8.x, and prior to version 1.9.6, the kubectl cp command insecurely handles tar data returned from the container, and can be caused to overwrite arbitrary local files.
Scope: local
bookworm: resolved (fixed in 1.17.4-1)
bullseye: resolved (fixed in 1.17.4-1)
forky: resolved (fixed in 1.17.4-1)
sid: resolved (fixe
debian
CVE-2020-8551P4MEDIUMCVSS 4.3fixed in kubernetes 1.17.4-1 (bookworm)2020
CVE-2020-8551 [MEDIUM] CVE-2020-8551: kubernetes - The Kubelet component in versions 1.15.0-1.15.9, 1.16.0-1.16.6, and 1.17.0-1.17....
The Kubelet component in versions 1.15.0-1.15.9, 1.16.0-1.16.6, and 1.17.0-1.17.2 has been found to be vulnerable to a denial of service attack via the kubelet API, including the unauthenticated HTTP read-only API typically served on port 10255, and the authenticated HTTPS API typically served on port 10250.
Scope: local
bookworm: resolved (fixed in 1.17.4-1)
bul
debian
CVE-2020-8565P4MEDIUMCVSS 4.7fixed in kubernetes 1.20.0-1 (bookworm)2020
CVE-2020-8565 [MEDIUM] CVE-2020-8565: kubernetes - In Kubernetes, if the logging level is set to at least 9, authorization and bear...
In Kubernetes, if the logging level is set to at least 9, authorization and bearer tokens will be written to log files. This can occur both in API server logs and client tool output like kubectl. This affects <= v1.19.3, <= v1.18.10, <= v1.17.13, < v1.20.0-alpha2.
Scope: local
bookworm: resolved (fixed in 1.20.0-1)
bullseye: resolved (fixed in 1.20.0-1)
forky: re
debian
CVE-2020-8557P4MEDIUMCVSS 5.5fixed in kubernetes 1.18.5-1 (bookworm)2020
CVE-2020-8557 [MEDIUM] CVE-2020-8557: kubernetes - The Kubernetes kubelet component in versions 1.1-1.16.12, 1.17.0-1.17.8 and 1.18...
The Kubernetes kubelet component in versions 1.1-1.16.12, 1.17.0-1.17.8 and 1.18.0-1.18.5 do not account for disk usage by a pod which writes to its own /etc/hosts file. The /etc/hosts file mounted in a pod by kubelet is not included by the kubelet eviction manager when calculating ephemeral storage usage by a pod. If a pod writes a large amount of data to the /e
debian
CVE-2020-8566P4MEDIUMCVSS 4.7fixed in kubernetes 1.19.3-1 (bookworm)2020
CVE-2020-8566 [MEDIUM] CVE-2020-8566: kubernetes - In Kubernetes clusters using Ceph RBD as a storage provisioner, with logging lev...
In Kubernetes clusters using Ceph RBD as a storage provisioner, with logging level of at least 4, Ceph RBD admin secrets can be written to logs. This occurs in kube-controller-manager's logs during provisioning of Ceph RBD persistent claims. This affects < v1.19.3, < v1.18.10, < v1.17.13.
Scope: local
bookworm: resolved (fixed in 1.19.3-1)
bullseye: resolved (fix
debian
CVE-2023-2431P4LOWCVSS 3.4fixed in kubernetes 1.20.5+really1.20.2-1 (bookworm)2023
CVE-2023-2431 [LOW] CVE-2023-2431: kubernetes - A security issue was discovered in Kubelet that allows pods to bypass the seccom...
A security issue was discovered in Kubelet that allows pods to bypass the seccomp profile enforcement. Pods that use localhost type for seccomp profile but specify an empty profile field, are affected by this issue. In this scenario, this vulnerability allows the pod to run in unconfined (seccomp disabled) mode. This bug affects Kubelet.
Scope: local
bookworm: resol
debian
CVE-2020-8564P4MEDIUMCVSS 4.7fixed in kubernetes 1.19.3-1 (bookworm)2020
CVE-2020-8564 [MEDIUM] CVE-2020-8564: kubernetes - In Kubernetes clusters using a logging level of at least 4, processing a malform...
In Kubernetes clusters using a logging level of at least 4, processing a malformed docker config file will result in the contents of the docker config file being leaked, which can include pull secrets or other registry credentials. This affects < v1.19.3, < v1.18.10, < v1.17.13.
Scope: local
bookworm: resolved (fixed in 1.19.3-1)
bullseye: resolved (fixed in 1.19
debian
CVE-2025-0426P4MEDIUMCVSS 6.2fixed in kubernetes 1.20.5+really1.20.2-1 (bookworm)2025
CVE-2025-0426 [MEDIUM] CVE-2025-0426: kubernetes - A security issue was discovered in Kubernetes where a large number of container ...
A security issue was discovered in Kubernetes where a large number of container checkpoint requests made to the unauthenticated kubelet read-only HTTP endpoint may cause a Node Denial of Service by filling the Node's disk.
Scope: local
bookworm: resolved (fixed in 1.20.5+really1.20.2-1)
bullseye: resolved (fixed in 1.20.5+really1.20.2-1)
forky: resolved (fixed in
debian
CVE-2020-8552P4MEDIUMCVSS 5.3fixed in kubernetes 1.17.4-1 (bookworm)2020
CVE-2020-8552 [MEDIUM] CVE-2020-8552: kubernetes - The Kubernetes API server component in versions prior to 1.15.9, 1.16.0-1.16.6, ...
The Kubernetes API server component in versions prior to 1.15.9, 1.16.0-1.16.6, and 1.17.0-1.17.2 has been found to be vulnerable to a denial of service attack via successful API requests.
Scope: local
bookworm: resolved (fixed in 1.17.4-1)
bullseye: resolved (fixed in 1.17.4-1)
forky: resolved (fixed in 1.17.4-1)
sid: resolved (fixed in 1.17.4-1)
trixie: resolve
debian