A security issue was discovered in kube-apiserver that could allow node updates to bypass a Validating Admission Webhook. Clusters are only affected by this vulnerability if they run a Validating Admission Webhook for Nodes that denies admission based at least partially on the old state of the Node object. Validating Admission Webhook does not observe some previous fields.
https://www.ibm.com/support/pages/node/6549374
https://www.ibm.com/support/pages/node/6447812
https://groups.google.com/g/kubernetes-security-announce/c/FKAGqT4jx9Y