Gardener Security Announcement - 0.11.0 released, please update immediately

98 views
Skip to first unread message

Frederik Thormaehlen

unread,
Oct 1, 2018, 9:13:07 AM10/1/18
to gardener

We have recently released Gardener 0.11.0 to address (beside new functionality) a security issue related to missing network isolation in the Gardener context and recommend all Gardener instances to update immediately to the Gardener release 0.11.0 or higher [1].


Following the Gardener architecture, the Kubernetes apiserver of a Gardener managed shoot cluster resides in the corresponding seed cluster. Due to missing network isolation a shoot’s apiserver can access services/endpoints in the private network of its corresponding seed cluster. Combined with other minor Kubernetes security issues, the missing network isolation theoretically can lead to compromise other shoot or seed clusters in the Gardener context. The issue is rated high due to the high impact on exploitation in the Gardener context.


There will soon a related Gardener specific CVE become available, which will be published in this group.


Thanks to Michael Schubert and Alban Crequy from Kinvolk for reporting this problem.


As a reminder, if you find a security vulnerability in Gardener, please report it following the Gardener security disclosure process [2] which is appropriate for your finding.


Thanks,

Frederik Thormaehlen

(on behalf of the Gardener Security Team)


[1] https://github.com/gardener/gardener/releases

[2] https://github.com/gardener/documentation/blob/master/security-release-process.md#disclosures

Reply all
Reply to author
Forward
0 new messages