​
DirectorySecurity Advisories
Sign In
Security Advisories

CGA-g94q-7p3f-f6h2

Published

Last updated

https://images.chainguard.dev/security/CGA-g94q-7p3f-f6h2
Package

kubernetes-1.22

Latest Update
Not affected
Aliases
  • CVE-2020-8554
  • GHSA-j9wf-vvm6-4r9w

Severity

5.0

Medium

CVSS V3

Summary

Unverified Ownership in Kubernetes

Description

Kubernetes API server in all versions allow an attacker who is able to create a ClusterIP service and set the spec.externalIPs field, to intercept traffic to that IP address. Additionally, an attacker who is able to patch the status (which is considered a privileged operation and should not typically be granted to users) of a LoadBalancer service can set the status.loadBalancer.ingress.ip to similar effect.

References

Updates


Safe Source for Open Sourceâ„¢
Media KitContact Us
© 2024 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Product

Chainguard Images