github.com/kube-vip/kube-vip is vulnerable to Improper Access Control
72
High Risk
Affected versions of this package are vulnerable to a Service Port Security Bypass, where the --onlyAllowTrafficServicePorts flag and enable_service_security setting fail to apply intended port restriction rules, allowing an attacker who can route traffic to a load balancer IP (e.g., via BGP with kube-vip) to access sensitive Kubernetes API ports (like 6443 and 10250) that should be blocked, thereby exposing the cluster's control plane and node endpoints.
You are affected if you are using a version that falls within the vulnerable range.
github.com/kube-vip/kube-vip is vulnerable to Improper Access Control in versions 1.0.0 - 1.0.2.
Upgrade the github.com/kube-vip/kube-vip library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant