CVE-2020-8558
Improper Authentication in Kubernetes in k8s.io/kubernetes
8.8
HIGH
CVSS 3.1
EPSS 20.1%
Description
The Kubelet and kube-proxy components in versions 1.1.0-1.16.10, 1.17.0-1.17.6, and 1.18.0-1.18.3 were found to contain a security issue which allows adjacent hosts to reach TCP and UDP services bound to 127.0.0.1 running on the node or in the node's network namespace. Such a service is generally thought to be reachable only by other processes on the same host, but due to this defeect, could be reachable by other hosts on the same LAN as the node, or by containers running on the same node as the service.
How to fix CVE-2020-8558
To remediate CVE-2020-8558, upgrade the affected package to a fixed version below.
- —upgrade to 1.18.5-1 or later
- —upgrade to 1.18.4 or later
- —upgrade to 1.16.11 or later
Is CVE-2020-8558 being exploited?
Moderate — EPSS is 20.1%. Track this CVE but it's not at the top of the prioritisation list.
Affected packages (3)
- from 0, < 1.18.5-1
- >= 1.18.0, < 1.18.4
- from 0, < 1.16.11, >= 1.17.0, < 1.17.7, >= 1.18.0, < 1.18.4
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH8.8 | CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |