Privilege Escalation in Kubernetes
        
  Critical severity
        
          GitHub Reviewed
      
        Published
          Feb 15, 2022 
          to the GitHub Advisory Database
          •
          Updated Jan 9, 2023 
      
  
Package
Affected versions
< 1.10.11
      >= 1.11.0, < 1.11.5
      >= 1.12.0, < 1.12.3
  Patched versions
1.10.11
      1.11.5
      1.12.3
  Description
        Reviewed
      May 20, 2021 
    
  
        Published to the GitHub Advisory Database
      Feb 15, 2022 
    
  
        Last updated
      Jan 9, 2023 
    
  
In all Kubernetes versions prior to v1.10.11, v1.11.5, and v1.12.3, incorrect handling of error responses to proxied upgrade requests in the kube-apiserver allowed specially crafted requests to establish a connection through the Kubernetes API server to backend servers, then send arbitrary requests over the same connection directly to the backend, authenticated with the Kubernetes API server's TLS credentials used to establish the backend connection.
References