Vulnerabilities > Kubernetes > Kubernetes > 1.20.0

DATE CVE VULNERABILITY TITLE RISK
2022-02-01 CVE-2020-8562 Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Kubernetes
As mitigations to a report from 2019 and CVE-2020-8555, Kubernetes attempts to prevent proxied connections from accessing link-local or localhost networks when making user-driven connections to Services, Pods, Nodes, or StorageClass service providers.
3.5
2021-09-20 CVE-2021-25741 Files or Directories Accessible to External Parties vulnerability in Kubernetes
A security issue was discovered in Kubernetes where a user may be able to create a container with subpath volume mounts to access files & directories outside of the volume, including on the host filesystem.
network
low complexity
kubernetes CWE-552
5.5
2021-09-06 CVE-2021-25735 Unspecified vulnerability in Kubernetes
A security issue was discovered in kube-apiserver that could allow node updates to bypass a Validating Admission Webhook.
network
low complexity
kubernetes
6.5
2021-09-06 CVE-2021-25737 Open Redirect vulnerability in Kubernetes
A security issue was discovered in Kubernetes where a user may be able to redirect pod traffic to private networks on a Node.
4.9