The API server in Kubernetes does not properly check admission control, which allows remote authenticated users to access additional resources via a crafted patched object.
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2016-1905.json"