CVE-2021-32783 is a high-severity vulnerability affecting Contour, a Kubernetes ingress controller, specifically versions prior to 1.17.1. It allows an attacker to use a specially crafted ExternalName type Service to access Envoy's administrative interface, which is normally restricted. This access can lead to a denial of service by shutting down Envoy or exposing the existence of secrets (like TLS keypairs), though not their content. The vulnerability has a CVSS score of 8.5 (High), indicating a network-based attack with low complexity, requiring low privileges, and resulting in high availability impact and low confidentiality impact. While it allows for administrative actions like shutting down or draining Envoy, it generally cannot be used to alter cluster configurations or in-flight requests. There is no evidence of active exploitation, nor are there publicly available exploit modules in Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage for this CVE are minimal, suggesting it has not garnered significant public attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.17.1CPE matchmatch criteria | cpe:2.3:a:projectcontour:contour:*:*:*:*:*:kubernetes:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.