Описание
Privilege Escalation in Kubernetes
The Kubernetes kube-apiserver in versions v1.6-v1.15, and versions prior to v1.16.13, v1.17.9 and v1.18.7 are vulnerable to an unvalidated redirect on proxied upgrade requests that could allow an attacker to escalate privileges from a node compromise to a full cluster compromise.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2020-8559
- https://github.com/kubernetes/kubernetes/issues/92914
- https://github.com/kubernetes/kubernetes/pull/92941
- https://bugzilla.redhat.com/show_bug.cgi?id=1851422
- https://github.com/tdwyer/CVE-2020-8559
- https://groups.google.com/d/msg/kubernetes-security-announce/JAIGG5yNROs/19nHQ5wkBwAJ
- https://groups.google.com/g/kubernetes-security-announce/c/JAIGG5yNROs
- https://security.netapp.com/advisory/ntap-20200810-0004
Пакеты
k8s.io/apimachinery
< 0.16.13
0.16.13
k8s.io/apimachinery
>= 0.17.0, < 0.17.9
0.17.9
k8s.io/apimachinery
>= 0.18.0, < 0.18.7
0.18.7
k8s.io/kubernetes
< 1.16.13
1.16.13
k8s.io/kubernetes
>= 1.17.0, < 1.17.9
1.17.9
k8s.io/kubernetes
>= 1.18.0, < 1.18.7
1.18.7
Связанные уязвимости
The Kubernetes kube-apiserver in versions v1.6-v1.15, and versions prior to v1.16.13, v1.17.9 and v1.18.6 are vulnerable to an unvalidated redirect on proxied upgrade requests that could allow an attacker to escalate privileges from a node compromise to a full cluster compromise.
The Kubernetes kube-apiserver in versions v1.6-v1.15, and versions prior to v1.16.13, v1.17.9 and v1.18.6 are vulnerable to an unvalidated redirect on proxied upgrade requests that could allow an attacker to escalate privileges from a node compromise to a full cluster compromise.
The Kubernetes kube-apiserver in versions v1.6-v1.15, and versions prior to v1.16.13, v1.17.9 and v1.18.6 are vulnerable to an unvalidated redirect on proxied upgrade requests that could allow an attacker to escalate privileges from a node compromise to a full cluster compromise.
The Kubernetes kube-apiserver in versions v1.6-v1.15, and versions pri ...