VYPR
Moderate severityNVD Advisory· Published Jul 22, 2020· Updated Sep 16, 2024

Privilege escalation from compromised node to cluster

CVE-2020-8559

Description

The Kubernetes kube-apiserver in versions v1.6-v1.15, and versions prior to v1.16.13, v1.17.9 and v1.18.6 are vulnerable to an unvalidated redirect on proxied upgrade requests that could allow an attacker to escalate privileges from a node compromise to a full cluster compromise.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
k8s.io/apimachineryGo
< 0.16.130.16.13
k8s.io/apimachineryGo
>= 0.17.0, < 0.17.90.17.9
k8s.io/apimachineryGo
>= 0.18.0, < 0.18.70.18.7
k8s.io/kubernetesGo
< 1.16.131.16.13
k8s.io/kubernetesGo
>= 1.17.0, < 1.17.91.17.9
k8s.io/kubernetesGo
>= 1.18.0, < 1.18.71.18.7

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

9

News mentions

0

No linked articles in our index yet.