Affected by GO-2022-0617
and 9 other vulnerabilities
GO-2022-0617 : WITHDRAWN: Potential proxy IP restriction bypass in Kubernetes in k8s.io/kubernetes
GO-2023-1891 : Vulnerable to policy bypass in kube-apiserver in k8s.io/kubernetes
GO-2023-1892 : Kubernetes mountable secrets policy bypass in k8s.io/kubernetes
GO-2023-2341 : Kubernetes Improper Input Validation vulnerability in k8s.io/kubernetes
GO-2024-2994 : Kubernetes sets incorrect permissions on Windows containers logs in k8s.io/kubernetes
GO-2025-3521 : Kubernetes GitRepo Volume Inadvertent Local Repository Access in k8s.io/kubernetes
GO-2025-3522 : Kubernetes allows Command Injection affecting Windows nodes via nodes/*/logs/query API in k8s.io/kubernetes
GO-2025-3547 : Kubernetes kube-apiserver Vulnerable to Race Condition in k8s.io/kubernetes
GO-2025-3915 : Kubernetes Nodes can delete themselves by adding an OwnerReference in k8s.io/kubernetes
GO-2025-4240 : Half-blind Server Side Request Forgery in kube-controller-manager through in-tree Portworx StorageClass in k8s.io/kubernetes
Discover Packages
k8s.io/kubernetes
plugin
pkg
admission
certificates
subjectrestriction
package
Version:
v1.27.2
Opens a new window with list of versions in this module.
Published: May 17, 2023
License: Apache-2.0
Opens a new window with license information.
Imports: 7
Opens a new window with list of imports.
Imported by: 6
Opens a new window with list of known importers.
Documentation
Documentation
¶
View Source
const PluginName = "CertificateSubjectRestriction"
PluginName is a string with the name of the plugin
Register registers the plugin
Plugin holds state for and implements the admission plugin.
NewPlugin constructs a new instance of the CertificateSubjectRestrictions admission interface.
Validate ensures that if the signerName on a CSR is set to
`kubernetes.io/kube-apiserver-client`, that its organization (group)
attribute is not set to `system:masters`.
ValidateInitialization always returns nil.
Source Files
¶
Click to show internal directories.
Click to hide internal directories.