Debian Kubernetes vulnerabilities
49 known vulnerabilities affecting debian/kubernetes.
Total CVEs
49
CISA KEV
0
Public exploits
3
Exploited in wild
1
Severity breakdown
CRITICAL2HIGH11MEDIUM26LOW10
Vulnerabilities
Page 3 of 3
CVE-2020-8561P4MEDIUMCVSS 4.1fixed in kubernetes 1.20.5+really1.20.2-1 (bookworm)2020
CVE-2020-8561 [MEDIUM] CVE-2020-8561: kubernetes - A security issue was discovered in Kubernetes where actors that control the resp...
A security issue was discovered in Kubernetes where actors that control the responses of MutatingWebhookConfiguration or ValidatingWebhookConfiguration requests are able to redirect kube-apiserver requests to private networks of the apiserver. If that user can view kube-apiserver logs when the log level is set to 10, they can view the redirected responses and hea
debian
CVE-2021-25737P4LOWCVSS 2.7fixed in kubernetes 1.20.5+really1.20.2-1 (bookworm)2021
CVE-2021-25737 [LOW] CVE-2021-25737: kubernetes - A security issue was discovered in Kubernetes where a user may be able to redire...
A security issue was discovered in Kubernetes where a user may be able to redirect pod traffic to private networks on a Node. Kubernetes already prevents creation of Endpoint IPs in the localhost or link-local range, but the same validation was not performed on EndpointSlice IPs.
Scope: local
bookworm: resolved (fixed in 1.20.5+really1.20.2-1)
bullseye: resolved (
debian
CVE-2021-25740P4LOWCVSS 3.1fixed in kubernetes 1.20.5+really1.20.2-1 (bookworm)2021
CVE-2021-25740 [LOW] CVE-2021-25740: kubernetes - A security issue was discovered with Kubernetes that could enable users to send ...
A security issue was discovered with Kubernetes that could enable users to send network traffic to locations they would otherwise not have access to via a confused deputy attack.
Scope: local
bookworm: resolved (fixed in 1.20.5+really1.20.2-1)
bullseye: resolved (fixed in 1.20.5+really1.20.2-1)
forky: resolved (fixed in 1.20.5+really1.20.2-1)
sid: resolved (fixed
debian
CVE-2024-3177P4LOWCVSS 2.7fixed in kubernetes 1.20.5+really1.20.2-1 (bookworm)2024
CVE-2024-3177 [LOW] CVE-2024-3177: kubernetes - A security issue was discovered in Kubernetes where users may be able to launch ...
A security issue was discovered in Kubernetes where users may be able to launch containers that bypass the mountable secrets policy enforced by the ServiceAccount admission plugin when using containers, init containers, and ephemeral containers with the envFrom field populated. The policy ensures pods running with a service account may only reference secrets specifi
debian
CVE-2020-8562P4MEDIUMCVSS 6.3fixed in kubernetes 1.20.5+really1.20.2-1 (bookworm)2020
CVE-2020-8562 [MEDIUM] CVE-2020-8562: kubernetes - As mitigations to a report from 2019 and CVE-2020-8555, Kubernetes attempts to p...
As mitigations to a report from 2019 and CVE-2020-8555, Kubernetes attempts to prevent proxied connections from accessing link-local or localhost networks when making user-driven connections to Services, Pods, Nodes, or StorageClass service providers. As part of this mitigation Kubernetes does a DNS name resolution check and validates that response IPs are not in
debian
CVE-2018-1002102P4LOWCVSS 2.6fixed in kubernetes 1.17.4-1 (bookworm)2018
CVE-2018-1002102 [LOW] CVE-2018-1002102: kubernetes - Improper validation of URL redirection in the Kubernetes API server in versions ...
Improper validation of URL redirection in the Kubernetes API server in versions prior to v1.14.0 allows an attacker-controlled Kubelet to redirect API server requests from streaming endpoints to arbitrary hosts. Impacted API servers will follow the redirect as a GET request with client-certificate credentials for authenticating to the Kubelet.
Scope: local
boo
debian
CVE-2021-25743P4LOWCVSS 3.0fixed in kubernetes 1.20.5+really1.20.2-1.1 (bookworm)2021
CVE-2021-25743 [LOW] CVE-2021-25743: kubernetes - kubectl does not neutralize escape, meta or control sequences contained in the r...
kubectl does not neutralize escape, meta or control sequences contained in the raw data it outputs to a terminal. This includes but is not limited to the unstructured string fields in objects such as Events.
Scope: local
bookworm: resolved (fixed in 1.20.5+really1.20.2-1.1)
bullseye: open
forky: resolved (fixed in 1.31.4+ds-1)
sid: resolved (fixed in 1.31.4+ds-1)
debian
CVE-2024-7598P4LOWCVSS 3.1fixed in kubernetes 1.20.5+really1.20.2-1 (bookworm)2024
CVE-2024-7598 [LOW] CVE-2024-7598: kubernetes - A security issue was discovered in Kubernetes where a malicious or compromised p...
A security issue was discovered in Kubernetes where a malicious or compromised pod could bypass network restrictions enforced by network policies during namespace deletion. The order in which objects are deleted during namespace termination is not defined, and it is possible for network policies to be deleted before the pods that they protect. This can lead to a bri
debian
CVE-2025-4563P4LOWCVSS 2.7fixed in kubernetes 1.20.5+really1.20.2-1 (bookworm)2025
CVE-2025-4563 [LOW] CVE-2025-4563: kubernetes - A vulnerability exists in the NodeRestriction admission controller where nodes c...
A vulnerability exists in the NodeRestriction admission controller where nodes can bypass dynamic resource allocation authorization checks. When the DynamicResourceAllocation feature gate is enabled, the controller properly validates resource claim statuses during pod status updates but fails to perform equivalent validation during pod creation. This allows a compro
debian
← Previous3 / 3