Kubernetes API server in all versions allow an attacker who is able to create a ClusterIP service and set the spec.externalIPs field, to intercept traffic to that IP address. Additionally, an attacker who is able to patch the status (which is considered a privileged operation and should not typically be granted to users) of a LoadBalancer service can set the status.loadBalancer.ingress.ip to similar effect.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:LKubernetes
APPKubernetesall versionsOracle Communications Cloud Native Core Network Slice Selection Function
APPOracle1.2.1Oracle Communications Cloud Native Core Policy
APPOracle1.15.0Oracle Communications Cloud Native Core Service Communication Proxy
APPOracle1.14.0
Related vulnerabilities
RCE w Spring Cloud Function poprzez złośliwy SpEL routing-expression
Spring4Shell — RCE przez data binding w Spring MVC/WebFlux na JDK 9+
RCE poprzez code injection w VMware Spring Cloud Gateway (Actuator endpoint)
Esri Portal for ArcGIS – brak uwierzytelnienia dla krytycznej funkcji API
Nieprawidłowa autoryzacja w Esri Portal for ArcGIS — obejście uprawnień