Kubernetes node components (kubelet, kubeadm, kubectl) that run and manage the container workloads.
Version: 1.36.5
Type: Service
License:
| Expand | CVE | Title | Status | |
|---|---|---|---|---|
| CVE-2020-8554 Open CVE-2020-8554 in a new tab | Kubernetes API server in all versions allow an attacker who is able to create a ClusterIP service and set the spec.externalIPs field, to intercept traffic to that IP address. Additionally, an attacker who is able to patch the status (which is considered a privileged operation and should not typically be granted to users) of a LoadBalancer service can set the status.loadBalancer.ingress.ip to similar effect. | Not affected | Medium | |
| GO-2025-3521 Open GO-2025-3521 in a new tab | Kubernetes GitRepo Volume Inadvertent Local Repository Access in k8s.io/kubernetes | Not affected | Unknown | |
| GO-2025-3547 Open GO-2025-3547 in a new tab | Kubernetes kube-apiserver Vulnerable to Race Condition in k8s.io/kubernetes | Not affected | Unknown |
Kubernetes API server in all versions allow an attacker who is able to create a ClusterIP service and set the spec.externalIPs field, to intercept traffic to that IP address. Additionally, an attacker who is able to patch the status (which is considered a privileged operation and should not typically be granted to users) of a LoadBalancer service can set the status.loadBalancer.ingress.ip to similar effect.
Kubernetes GitRepo Volume Inadvertent Local Repository Access in k8s.io/kubernetes
Kubernetes kube-apiserver Vulnerable to Race Condition in k8s.io/kubernetes