Vulnerability CVE-2021-25736


Published: 2023-10-30

Description:
Kube-proxy
on Windows can unintentionally forward traffic to local processes
listening on the same port (??spec.ports[*].port?) as a LoadBalancer
Service when the LoadBalancer controller
does not set the ??status.loadBalancer.ingress[].ip? field. Clusters
where the LoadBalancer controller sets the
??status.loadBalancer.ingress[].ip? field are unaffected.

 References:
https://github.com/kubernetes/kubernetes/pull/99958
https://groups.google.com/g/kubernetes-security-announce/c/lIoOPObO51Q/m/O15LOazPAgAJ

Copyright 2026, cxsecurity.com

 

Back to Top