VDB
GO-2022-0703
GO-2022-0703
PUBLISHED
XML Entity Expansion and Improper Input Validation in Kubernetes API server in k8s.io/kubernetes
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| k8s.io | kubernetes | 1.0.0, 1.14.0, 1.15.0 |
Timeline
- Aug 21, 2024 CVE Published
- Feb 4, 2026 CVE Updated
- May 1, 2026 Distribution Patch
- May 1, 2026 Distribution Patch
- May 1, 2026 Distribution Patch
References
- https://github.com/advisories/GHSA-pmqp-h87c-mr78 advisory
- https://access.redhat.com/errata/RHSA-2019:3239 url
- https://access.redhat.com/errata/RHSA-2019:3811 url
- https://access.redhat.com/errata/RHSA-2019:3905 url
- https://gist.github.com/bgeesaman/0e0349e94cd22c48bf14d8a9b7d6b8f2 url
- https://github.com/kubernetes/kubernetes/issues/83253 url
- https://github.com/kubernetes/kubernetes/pull/83261 url
- https://groups.google.com/forum/#!topic/kubernetes-security-announce/jk8polzSUxs url
- https://security.netapp.com/advisory/ntap-20191031-0006 url