Register for the AI for Security Summit: Join Figma, Perplexity & Wiz

CVE-2021-25735
Jenkins vulnerability analysis and mitigation

Overview

A security issue (CVE-2021-25735) was discovered in Kubernetes kube-apiserver that could allow node updates to bypass a Validating Admission Webhook. The vulnerability affects kube-apiserver versions v1.20.0-v1.20.5, v1.19.0-v1.19.9, and versions <= v1.18.17. This medium-severity vulnerability (CVSS score: 6.5) only impacts environments using Validating Admission Webhook for nodes that bases admission decisions on the old state of Node objects (Kubernetes Issue, Sysdig Blog).

Technical details

The vulnerability occurs when an update action is performed on node resources with an admission controller configured to validate the action. The issue stems from the kube-apiserver incorrectly handling request.object and request.oldObject passed to the Validating Admission Webhook. Specifically, Node.ObjectMeta overwrites the old values which may be used for admission decisions, and since this overwriting happens before admission evaluation, it can lead to unauthorized changes in cluster nodes (Sysdig Blog).

Impact

The vulnerability has a low attack complexity and a high impact on integrity and confidentiality. When exploited, it allows attackers to completely bypass the controls in place in the Validating Admission Controller over nodes updates, enabling unauthorized changes to node settings without being stopped by the admission controller (Sysdig Blog).

Exploitability

The vulnerability can be exploited when both conditions are met: using Validating Admission Webhook for nodes and using Validating Admission Webhook with old values. The exploitation allows adversaries to bypass the Validating Admission Webhook checks and perform unauthorized update actions on Kubernetes nodes (Sysdig Blog).

Mitigation and workarounds

The vulnerability has been fixed in kube-apiserver versions v1.21.0, v1.20.6, v1.19.10, and v1.18.18. For systems that cannot be immediately patched, it's recommended to implement detection mechanisms such as Falco with Kubernetes Audit Logging enabled to monitor for exploitation attempts (Sysdig Blog, Kubernetes Issue).

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Alpine

Fixed

edge

k3s: 1.20.6.1-r0

Fixed

v3.18

k3s: 1.20.6.1-r0

Fixed

v3.19

k3s: 1.20.6.1-r0

Fixed

v3.20

k3s: 1.20.6.1-r0

Fixed

v3.21

k3s: 1.20.6.1-r0

Fixed

v3.22

k3s: 1.20.6.1-r0

Fixed

v3.23

k3s: 1.20.6.1-r0

Fixed

Arch Linux

Fixed

rolling

kube-apiserver: 1.21.0-1

Fixed

SourceThis report was generated using AI

Related Jenkins vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-84654MEDIUM5.4
  • Jenkins logoJenkins
  • jenkins
NoYesSep 02, 2026
CVE-2026-84656MEDIUM4.3
  • Jenkins logoJenkins
  • jenkins
NoYesSep 02, 2026
CVE-2026-84655MEDIUM4.3
  • Jenkins logoJenkins
  • cpe:2.3:a:jenkins:jenkins
NoYesSep 02, 2026
CVE-2026-84657MEDIUM4.2
  • Jenkins logoJenkins
  • jenkins
NoYesSep 02, 2026
CVE-2026-84653LOW3.5
  • Jenkins logoJenkins
  • cpe:2.3:a:jenkins:jenkins
NoYesSep 02, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management