This issue has been rated Medium (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H), and assigned CVE-2021-25735.
Note: This only impacts validating admission plugins that rely on old values in certain fields, and does not impact calls from kubelets that go through the built-in NodeRestriction admission plugin.
kube-apiserver v1.20.0 - v1.20.5
kube-apiserver v1.19.0 - v1.19.9
kube-apiserver <= v1.18.17
This issue is fixed in the following versions:
kube-apiserver v1.21.0
kube-apiserver v1.20.6
kube-apiserver v1.19.10
kube-apiserver v1.18.18
If you find evidence that this vulnerability has been exploited, please contact secu...@kubernetes.io
See Kubernetes Issue #100096 for more details.
This vulnerability was reported by Rogerio Bastos & Ari Lima from RedHat
Thank You,
Tim Allclair on behalf of the Kubernetes Product Security Committee