CVE-2020-8558
Last modified
CVE-2020-8558 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. The Kubelet and kube-proxy components in versions 1.1.0-1.16.10, 1.17.0-1.17.6, and 1.18.0-1.18.3 were found to contain a security issue which allows adjacent hosts to reach TCP and UDP services bound to 127.0.0.1 running on the node or in the node's network namespace. Such a service is generally thought to be reachable only by other processes on the same host, but due to this defeect, could be reachable by other hosts on the same LAN as the node, or by containers running on the same node as the service.. EPSS estimates a 3.60% chance of exploitation in the next 30 days.
Description
The Kubelet and kube-proxy components in versions 1.1.0-1.16.10, 1.17.0-1.17.6, and 1.18.0-1.18.3 were found to contain a security issue which allows adjacent hosts to reach TCP and UDP services bound to 127.0.0.1 running on the node or in the node's network namespace. Such a service is generally thought to be reachable only by other processes on the same host, but due to this defeect, could be reachable by other hosts on the same LAN as the node, or by containers running on the same node as the service.
Metrics
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Kubernetes | Kubernetes | >= 1.1.0, <= 1.16.10 |
| Kubernetes | Kubernetes | >= 1.17.0, <= 1.17.6 |
| Kubernetes | Kubernetes | >= 1.18.0, <= 1.18.3 |
References
- https://github.com/kubernetes/kubernetes/issues/92315Exploit, Mitigation, Patch, Third Party Advisory
- https://groups.google.com/g/kubernetes-announce/c/sI4KmlH3S2I/m/TljjxOBvBQAJExploit, Mailing List, Mitigation, Third Party Advisory
- https://security.netapp.com/advisory/ntap-20200821-0001/Third Party Advisory
- https://github.com/kubernetes/kubernetes/issues/92315Exploit, Mitigation, Patch, Third Party Advisory
- https://groups.google.com/g/kubernetes-announce/c/sI4KmlH3S2I/m/TljjxOBvBQAJExploit, Mailing List, Mitigation, Third Party Advisory
- https://security.netapp.com/advisory/ntap-20200821-0001/Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2020-8558?
How severe is CVE-2020-8558?
How do I fix CVE-2020-8558?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2020
- CVE-2020-8551The Kubelet component in versions 1.15.0-1.15.9, 1.16.0-1.16…6.5
- CVE-2020-8552The Kubernetes API server component in versions prior to 1.1…4.3
- CVE-2020-8553The Kubernetes ingress-nginx component prior to version 0.28…5.9
- CVE-2020-8554Kubernetes API server in all versions allow an attacker who …5
- CVE-2020-8555The Kubernetes kube-controller-manager in versions v1.0-1.14…6.3
- CVE-2020-8557The Kubernetes kubelet component in versions 1.1-1.16.12, 1.…5.5
- CVE-2020-8559The Kubernetes kube-apiserver in versions v1.6-v1.15, and ve…6.8
- CVE-2020-8561A security issue was discovered in Kubernetes where actors t…4.1
- CVE-2020-8562As mitigations to a report from 2019 and CVE-2020-8555, Kube…3.1
- CVE-2020-8563In Kubernetes clusters using VSphere as a cloud provider, wi…5.5
- CVE-2020-8564In Kubernetes clusters using a logging level of at least 4, …5.5
- CVE-2020-8565In Kubernetes, if the logging level is set to at least 9, au…5.5
Are you affected by CVE-2020-8558?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
