{
  "threat_severity" : "Moderate",
  "public_date" : "2021-04-14T00:00:00Z",
  "bugzilla" : {
    "description" : "kubernetes: Validating Admission Webhook does not observe some previous fields",
    "id" : "1937562",
    "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=1937562"
  },
  "cvss3" : {
    "cvss3_base_score" : "6.5",
    "cvss3_scoring_vector" : "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H",
    "status" : "verified"
  },
  "cwe" : "CWE-20",
  "details" : [ "A security issue was discovered in kube-apiserver that could allow node updates to bypass a Validating Admission Webhook. Clusters are only affected by this vulnerability if they run a Validating Admission Webhook for Nodes that denies admission based at least partially on the old state of the Node object. Validating Admission Webhook does not observe some previous fields.", "A vulnerability was found in Kubernetes' kube-apiserver that could allow Node updates to bypass a Validating Admission Webhook. An authenticated user could exploit this by modifying Node properties to values that should have been prevented by registered admission webhooks." ],
  "acknowledgement" : "Red Hat would like to thank the Kubernetes Product Security Committee for reporting this issue. Upstream acknowledges Ari Lima (Red Hat) and Rogerio Bastos (Red Hat) as the original reporters.",
  "affected_release" : [ {
    "product_name" : "Red Hat OpenShift Container Platform 4.8",
    "release_date" : "2021-07-27T00:00:00Z",
    "advisory" : "RHSA-2021:2437",
    "cpe" : "cpe:/a:redhat:openshift:4.8::el7",
    "package" : "openshift-0:4.8.0-202107161820.p0.git.051ac4f.assembly.stream.el7"
  } ],
  "package_state" : [ {
    "product_name" : "Red Hat OpenShift Container Platform 3.11",
    "fix_state" : "Will not fix",
    "package_name" : "atomic-openshift",
    "cpe" : "cpe:/a:redhat:openshift:3.11"
  } ],
  "references" : [ "https://www.cve.org/CVERecord?id=CVE-2021-25735\nhttps://nvd.nist.gov/vuln/detail/CVE-2021-25735\nhttps://groups.google.com/g/kubernetes-security-announce/c/FKAGqT4jx9Y" ],
  "name" : "CVE-2021-25735",
  "csaw" : false
}