ZeroHour

CVE-2020-8554

PoC
CVSS 3.1
5.0 medium
EPSS
9%p95
Published
()
Modified
Description

Kubernetes API server in all versions allow an attacker who is able to create a ClusterIP service and set the spec.externalIPs field, to intercept traffic to that IP address. Additionally, an attacker who is able to patch the status (which is considered a privileged operation and should not typically be granted to users) of a LoadBalancer service can set the status.loadBalancer.ingress.ip to similar effect.

Vendors
kubernetesoracle
Products
kubernetes, communications cloud native core network slice selection function, communications cloud native core policy, communications cloud native core service communication proxy
Weakness
CWE-283
Vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L

In the news