Medium severity4.3NVD Advisory· Published Mar 27, 2020· Updated Jun 17, 2026
CVE-2020-8551
CVE-2020-8551
Description
The Kubelet component in versions 1.15.0-1.15.9, 1.16.0-1.16.6, and 1.17.0-1.17.2 has been found to be vulnerable to a denial of service attack via the kubelet API, including the unauthenticated HTTP read-only API typically served on port 10255, and the authenticated HTTPS API typically served on port 10250.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
k8s.io/kubernetesGo | >= 1.15.0, < 1.15.10 | 1.15.10 |
k8s.io/kubernetesGo | >= 1.16.0, < 1.16.6 | 1.16.6 |
k8s.io/kubernetesGo | >= 1.17.0, < 1.17.2 | 1.17.2 |
Affected products
6cpe:2.3:a:kubernetes:kubernetes:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:kubernetes:kubernetes:*:*:*:*:*:*:*:*range: >=1.15.0,<=1.15.9
- (no CPE)range: unspecified
- cpe:2.3:o:fedoraproject:fedora:32:*:*:*:*:*:*:*
- osv-coords3 versionspkg:apk/chainguard/kubernetes-dns-node-cache-1.17pkg:golang/k8s.io/kubernetespkg:rpm/opensuse/govulncheck-vulndb&distro=openSUSE%20Tumbleweed
< 0+ 2 more
- (no CPE)range: < 0
- (no CPE)range: >= 1.15.0, < 1.15.10
- (no CPE)range: < 0.0.20250807T150727-1.1
Patches
Vulnerability mechanics
References
11- github.com/kubernetes/kubernetes/issues/89377nvdIssue TrackingPatchThird Party AdvisoryWEB
- github.com/advisories/GHSA-qhm4-jxv7-j9pqghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2020-8551ghsaADVISORY
- security.netapp.com/advisory/ntap-20200413-0003/nvdThird Party Advisory
- github.com/kubernetes/kubernetes/commit/9802bfcec0580169cffce2a3d468689a407fa7dcghsaWEB
- github.com/kubernetes/kubernetes/pull/87913ghsaWEB
- groups.google.com/forum/ghsaWEB
- lists.fedoraproject.org/archives/list/[email protected]/message/3SOCLOPTSYABTE4CLTSPDIFE6ZZZR4LXghsaWEB
- security.netapp.com/advisory/ntap-20200413-0003ghsaWEB
- groups.google.com/forum/nvd
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3SOCLOPTSYABTE4CLTSPDIFE6ZZZR4LX/nvd
News mentions
0No linked articles in our index yet.