CVE Feed

    Dashboard / CVE / CVE-2020-8558

    CVE-2020-8558

    The Kubelet and kube-proxy components in versions 1.1.0-1.16.10, 1.17.0-1.17.6, and 1.18.0-1.18.3 were found to contain a security issue which allows adjacent hosts to reach TCP and UDP services bound to 127.0.0.1 running on the node or in the node's network namespace. Such a service is generally thought to be reachable only by other processes on the same host, but due to this defeect, could be reachable by other hosts on the same LAN as the node, or by containers running on the same node as the service.

    Published:Jul 8, 2020
    Last Modified:Nov 21, 2024
    EPS:Jul 27, 2020
    EPSS Score:0.24176
    CVSS Score:5.4

    Affected Products

    Vendor
    Kubernetes
    Product
    Kubernetes
    Vendor
    Redhat
    Product
    Openshift

    Related CVEs

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High