Overview
About vulnerability
A vulnerability exists in the NodeRestriction admission controller in Kubernetes clusters where node users can delete their corresponding node object by patching themselves with an OwnerReference to a cluster-scoped resource. If the OwnerReference resource does not exist or is subsequently deleted, the given node object will be deleted via garbage collection.Details
- Affected product:
- argocd , argoproj/gitops-engine , kubernetes/kubernetes
- Affected packages:
- k8s.io/kubernetes @ 1.32.2 (+2 more)