CVE-2021-25736

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
30/10/2023
Last modified:
12/06/2025

Description

Kube-proxy<br /> on Windows can unintentionally forward traffic to local processes <br /> listening on the same port (“spec.ports[*].port”) as a LoadBalancer <br /> Service when the LoadBalancer controller<br /> does not set the “status.loadBalancer.ingress[].ip” field. Clusters <br /> where the LoadBalancer controller sets the <br /> “status.loadBalancer.ingress[].ip” field are unaffected.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:kubernetes:kubernetes:*:*:*:*:*:*:*:* 1.18.0 (including) 1.18.18 (excluding)
cpe:2.3:a:kubernetes:kubernetes:*:*:*:*:*:*:*:* 1.19.0 (including) 1.19.10 (excluding)
cpe:2.3:a:kubernetes:kubernetes:*:*:*:*:*:*:*:* 1.20.0 (including) 1.20.6 (excluding)
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*