The API server in Kubernetes does not properly check admission control, which allows remote authenticated users to access additional resources via a crafted patched object.
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
Link | Tags |
---|---|
https://github.com/kubernetes/kubernetes/issues/19479 | |
https://access.redhat.com/errata/RHSA-2016:0070 | vendor advisory |