4.3
CVSSv3

CVE-2020-8552

Published: 27/03/2020 Updated: 07/11/2023
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
CVSS v3 Base Score: 4.3 | Impact Score: 1.4 | Exploitability Score: 2.8
VMScore: 357
Vector: AV:N/AC:L/Au:S/C:N/I:N/A:P

Vulnerability Summary

The Kubernetes API server component in versions before 1.15.9, 1.16.0-1.16.6, and 1.17.0-1.17.2 has been found to be vulnerable to a denial of service attack via successful API requests.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

kubernetes kubernetes

fedoraproject fedora 32

Vendor Advisories

Synopsis Moderate: OpenShift Container Platform 4229 openshift security update Type/Severity Security Advisory: Moderate Topic An update for openshift is now available for Red Hat OpenShift Container Platform 42Red Hat Product Security has rated this update as having a security impact of Moderate A Com ...
Synopsis Moderate: OpenShift Container Platform 4229 openshift-enterprise-hyperkube-container security update Type/Severity Security Advisory: Moderate Topic An update for openshift-enterprise-hyperkube-container is now available for Red Hat OpenShift Container Platform 42Red Hat Product Security has ra ...
Synopsis Moderate: OpenShift Container Platform 4234 ose-openshift-apiserver-container security update Type/Severity Security Advisory: Moderate Topic An update for ose-openshift-apiserver-container is now available for Red Hat OpenShift Container Platform 42Red Hat Product Security has rated this updat ...
Synopsis Moderate: OpenShift Container Platform 439 ose-openshift-apiserver-container security update Type/Severity Security Advisory: Moderate Topic An update for ose-openshift-apiserver-container is now available for Red Hat OpenShift Container Platform 43Red Hat Product Security has rated this update ...
Synopsis Moderate: OpenShift Container Platform 311 security update Type/Severity Security Advisory: Moderate Topic An update for atomic-openshift, atomic-openshift-web-console, and cri-o is now available for Red Hat OpenShift Container Platform 311Red Hat Product Security has rated this update as having ...

Mailing Lists

<!--X-Body-Begin--> <!--X-User-Header--> oss-sec mailing list archives <!--X-User-Header-End--> <!--X-TopPNI--> By Date By Thread </form> <!--X-TopPNI-End--> <!--X-MsgBody--> <!--X-Subject-Header-Begin--> CVE-2020-8551, CVE-2020-8552: Kubernetes: Denial of service <!--X-Subject-Header-End--> <!--X-Head-of-Message--> From: Tim A ...

Github Repositories

Certified Kubernetes Security Specialist (CKS) Coming soon November 2020 Online resources that will help you prepare for taking the Kubernetes Certified Kubernetes Security Specialist Certification exam Disclaimer: This is not likely a comprehensive list as the exam is not out yet, most likely will be a moving target with the fast pace of k8s development please make a pull re

CKS 官方考纲 CKS 官方考纲: [CKS_Curriculum_ v119pdf](/CKS_Curriculum_ v119pdf) Cluster Setup - 10% Securing a Cluster Use Network security policies to restrict cluster level access kubernetesio/docs/concepts/services-networking/network-policies/ Use CIS benchmark to review the security configuration of Kubernetes components(etcd, kubelet, kubedns, ku

Learning how to deploy a simple 3 nodes (1 server and 2 agents) k3s cluster with rancher ui installed through a docker-compose.

Rancher/k3s cluster in docker containers Learning how to deploy a simple 3 nodes (1 server and 2 agents) k3s cluster with rancher ui installed through a docker-compose Environment It's possible to define env variables in a env file at the same level of the docker compose file ENV: K3S_VERSION: official rancher/k3s image version (default latest) K3S_URL: server url K3S_