6.8
CVSSv3

CVE-2020-8559

Published: 22/07/2020 Updated: 27/01/2023
CVSS v2 Base Score: 6 | Impact Score: 6.4 | Exploitability Score: 6.8
CVSS v3 Base Score: 6.8 | Impact Score: 5.9 | Exploitability Score: 0.9
VMScore: 535
Vector: AV:N/AC:M/Au:S/C:P/I:P/A:P

Vulnerability Summary

The Kubernetes kube-apiserver in versions v1.6-v1.15, and versions prior to v1.16.13, v1.17.9 and v1.18.6 are vulnerable to an unvalidated redirect on proxied upgrade requests that could allow an malicious user to escalate privileges from a node compromise to a full cluster compromise.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

kubernetes kubernetes

Vendor Advisories

Synopsis Important: OpenShift Container Platform 4433 bug fix and security update Type/Severity Security Advisory: Important Topic Red Hat OpenShift Container Platform release 4433 is now available withupdates to packages and images that fix several bugs and add enhancementsThis release also includes a ...
Synopsis Moderate: OpenShift Container Platform 311343 security and bug fix update Type/Severity Security Advisory: Moderate Topic Red Hat OpenShift Container Platform release 311343 is now available withupdates to packages and images that fix several bugsThis release includes a security update for Kub ...
Synopsis Moderate: OpenShift Container Platform 4521 bug fix and security update Type/Severity Security Advisory: Moderate Topic Red Hat OpenShift Container Platform release 4521 is now available with updates to packages and images that fix several bugsThis release includes a security update for opensh ...
Synopsis Moderate: OpenShift Container Platform 4432 packages and security update Type/Severity Security Advisory: Moderate Topic Red Hat OpenShift Container Platform release 4432 is now available withupdates to packages and images that fix several bugs and add enhancementsThis release also includes a ...
Synopsis Important: Migration Toolkit for Containers (MTC) 174 security and bug fix update Type/Severity Security Advisory: Important Topic The Migration Toolkit for Containers (MTC) 174 is now availableRed Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability Scoring System (CVSS) ba ...
Synopsis Moderate: OpenShift Container Platform 461 image security update Type/Severity Security Advisory: Moderate Topic An update is now available for Red Hat OpenShift Container Platform 46Red Hat Product Security has rated this update as having a security impact of Moderate A Common Vulnerability S ...

Mailing Lists

<!--X-Body-Begin--> <!--X-User-Header--> oss-sec mailing list archives <!--X-User-Header-End--> <!--X-TopPNI--> By Date By Thread </form> <!--X-TopPNI-End--> <!--X-MsgBody--> <!--X-Subject-Header-Begin--> Kubernetes: CVE-2020-8559: Privilege escalation from compromised node to cluster <!--X-Subject-Header-End--> <!--X-Head-of-Mes ...

Github Repositories

This is a PoC exploit for CVE-2020-8559 Kubernetes Vulnerability

Kubernetes CVE-2020-8559 Proof of Concept PoC Exploit This is for demonstration purposes only Only for use on systems you are authorized to preform administrative actions on and are authorized to exploit CVE-2020-8559 on This is a PoC for CVE-2020-8559 This vulnerability allows an attacker who has gotten root on a Node to execute commands on any other Container in the cluster

katlol/stars - An awesome list of my starred repositories

Awesome Stars A curated list of my GitHub stars! Generated by starred Contents AGS Script ActionScript Adblock Filter List Assembly Batchfile C C# C++ CSS Clojure CoffeeScript Crystal D Dart Dockerfile Elixir Elm Emacs Lisp Go HCL HTML Hack Haskell Inno Setup Java JavaScript Jinja Jsonnet Julia Jupyter Notebook Kotlin Less Logos Lua MATLAB MDX Makefile Markdown Mathematica

katlol/stars - An awesome list of my starred repositories

Awesome Stars A curated list of my GitHub stars! Generated by starred Contents AGS Script ActionScript Adblock Filter List Assembly Batchfile C C# C++ CSS Clojure CoffeeScript Crystal D Dart Dockerfile Elixir Elm Emacs Lisp Go HCL HTML Hack Haskell Inno Setup Java JavaScript Jinja Jsonnet Julia Jupyter Notebook Kotlin Less Logos Lua MATLAB MDX Makefile Markdown Mathematica