CVE-2020-8562

Related Vulnerabilities: CVE-2020-8562  

A security issue was discovered in Kubernetes where an authorized user may be able to access private networks on the Kubernetes control plane components. Kubernetes clusters are only affected if an untrusted user can create or modify Node objects and proxy to them, or an untrusted user can create or modify StorageClass objects and access KubeControllerManager logs.

Description

A security issue was discovered in Kubernetes where an authorized user may be able to access private networks on the Kubernetes control plane components. Kubernetes clusters are only affected if an untrusted user can create or modify Node objects and proxy to them, or an untrusted user can create or modify StorageClass objects and access KubeControllerManager logs.

Additional Information

  • Bugzilla 1954914: CVE-2020-8562 kubernetes: Bypass of Kubernetes API Server proxy TOCTOU
  • CWE-367: Time-of-check Time-of-use (TOCTOU) Race Condition
  • FAQ: Frequently asked questions about CVE-2020-8562