Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2020-8557

Опубликовано: 23 июл. 2020
Источник: nvd
CVSS3: 5.5
CVSS2: 2.1
EPSS Низкий

Описание

The Kubernetes kubelet component in versions 1.1-1.16.12, 1.17.0-1.17.8 and 1.18.0-1.18.5 do not account for disk usage by a pod which writes to its own /etc/hosts file. The /etc/hosts file mounted in a pod by kubelet is not included by the kubelet eviction manager when calculating ephemeral storage usage by a pod. If a pod writes a large amount of data to the /etc/hosts file, it could fill the storage space of the node and cause the node to fail.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:kubernetes:kubernetes:*:*:*:*:*:*:*:*
Версия до 1.16.13 (исключая)
cpe:2.3:a:kubernetes:kubernetes:*:*:*:*:*:*:*:*
Версия от 1.17.0 (включая) до 1.17.9 (исключая)
cpe:2.3:a:kubernetes:kubernetes:*:*:*:*:*:*:*:*
Версия от 1.18.0 (включая) до 1.18.6 (исключая)

EPSS

Процентиль: 39%
0.00172
Низкий

5.5 Medium

CVSS3

2.1 Low

CVSS2

Дефекты

CWE-400
CWE-400

Связанные уязвимости

CVSS3: 5.5
ubuntu
почти 5 лет назад

The Kubernetes kubelet component in versions 1.1-1.16.12, 1.17.0-1.17.8 and 1.18.0-1.18.5 do not account for disk usage by a pod which writes to its own /etc/hosts file. The /etc/hosts file mounted in a pod by kubelet is not included by the kubelet eviction manager when calculating ephemeral storage usage by a pod. If a pod writes a large amount of data to the /etc/hosts file, it could fill the storage space of the node and cause the node to fail.

CVSS3: 5.5
redhat
почти 5 лет назад

The Kubernetes kubelet component in versions 1.1-1.16.12, 1.17.0-1.17.8 and 1.18.0-1.18.5 do not account for disk usage by a pod which writes to its own /etc/hosts file. The /etc/hosts file mounted in a pod by kubelet is not included by the kubelet eviction manager when calculating ephemeral storage usage by a pod. If a pod writes a large amount of data to the /etc/hosts file, it could fill the storage space of the node and cause the node to fail.

CVSS3: 5.5
debian
почти 5 лет назад

The Kubernetes kubelet component in versions 1.1-1.16.12, 1.17.0-1.17. ...

suse-cvrf
почти 5 лет назад

Bugfixes on cilium, gangway and skuba and security fix for Kubernetes (cve-2020-8557)

CVSS3: 5.5
github
около 1 года назад

Denial of service in Kubernetes

EPSS

Процентиль: 39%
0.00172
Низкий

5.5 Medium

CVSS3

2.1 Low

CVSS2

Дефекты

CWE-400
CWE-400