CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Unpatchable Vulnerabilities of Kubernetes: CVE-2021-25740

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 6668

As cited

Copy frozen at (site build).

vulnerabilities

Unpatchable Vulnerabilities of Kubernetes: CVE-2021-25740

Kubernetes CVE-2021-25740 enables users with EndpointSlice access to redirect traffic through shared ingress and load balancer services. The vulnerability permits lateral movement and traffic interception within a cluster by exploiting insufficient access controls on endpoint objects.

Why it matters: Kubernetes operators and platform teams must audit EndpointSlice role-based access control (RBAC) permissions to prevent unprivileged cluster users from hijacking traffic destined for shared services.

VendorsKubernetes
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary