CVE-2020-8554
21.01.2021, 17:15
Kubernetes API server in all versions allow an attacker who is able to create a ClusterIP service and set the spec.externalIPs field, to intercept traffic to that IP address. Additionally, an attacker who is able to patch the status (which is considered a privileged operation and should not typically be granted to users) of a LoadBalancer service can set the status.loadBalancer.ingress.ip to similar effect.Enginsight
Vendor | Product | Version |
---|---|---|
kubernetes | kubernetes | * |
oracle | communications_cloud_native_core_network_slice_selection_function | 1.2.1 |
oracle | communications_cloud_native_core_policy | 1.15.0 |
oracle | communications_cloud_native_core_service_communication_proxy | 1.14.0 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Common Weakness Enumeration
References