Total vulnerabilities in the database
The Kubernetes kube-controller-manager in versions v1.0-1.14, versions prior to v1.15.12, v1.16.9, v1.17.5, and version v1.18.0 are vulnerable to a Server Side Request Forgery (SSRF) that allows certain authorized users to leak up to 500 bytes of arbitrary information from unprotected endpoints within the master's host network (such as link-local or loopback services).
Software | From | Fixed in |
---|---|---|
kubernetes / kubernetes | 1.18.0 | 1.18.0.x |
kubernetes / kubernetes | - | 1.15.11 |
kubernetes / kubernetes | 1.17.0 | 1.17.5 |
kubernetes / kubernetes | 1.16.0 | 1.16.9 |
fedoraproject / fedora | 32 | 32.x |
![]() |
1.18.0 | 1.18.1 |
![]() |
1.17.0 | 1.17.4 |
![]() |
1.16.0 | 1.16.9 |
![]() |
- | 1.15.12 |