Description
A vulnerability exists in the NodeRestriction admission controller in Kubernetes clusters where node users can delete their corresponding node object by patching themselves with an OwnerReference to a cluster-scoped resource. If the OwnerReference resource does not exist or is subsequently deleted, the given node object will be deleted via garbage collection.
Problem types
CWE-863 Incorrect Authorization
Product status
v1.31.0
v1.32.0
v1.33.0
Credits
Paul Viossat
References
github.com/kubernetes/kubernetes/issues/133471
groups.google.com/...ernetes-security-announce/c/znSNY7XCztE