Skip to content

H3-2021-0005

Unauthenticated Kubelet API Remote Code Execution Vulnerability

Category SECURITY_MISCONFIGURATION
Base Score 9.8

Description

The kubelet exposes one or more endpoints as part of the kubelet’s debug handlers.

Impact

An attacker could execute arbitrary commands on a container and retrieve sensitive information from the container.

References