Lucene search

K
redhatcveRedhat.comRH:CVE-2020-8555
HistoryJun 01, 2020 - 9:22 p.m.

CVE-2020-8555

2020-06-0121:22:25
redhat.com
access.redhat.com
20

EPSS

0.001

Percentile

41.5%

A server side request forgery (SSRF) flaw was found in Kubernetes. The kube-controller-manager allows authorized users with the ability to create StorageClasses or certain Volume types to leak up to 500 bytes of arbitrary information from the masterโ€™s host network. This can include secrets from the kube-apiserver through the unauthenticated localhost port (if enabled).

Mitigation

Restrict use of the vulnerable volume type and restrict StorageClass write permissions via RBAC