CVE-2020-8559

Severity CVSS v4.0:
Pending analysis
Type:
CWE-601 URL Redirection to Untrusted Site ('Open Redirect')
Publication date:
22/07/2020
Last modified:
27/01/2023

Description

The Kubernetes kube-apiserver in versions v1.6-v1.15, and versions prior to v1.16.13, v1.17.9 and v1.18.6 are vulnerable to an unvalidated redirect on proxied upgrade requests that could allow an attacker to escalate privileges from a node compromise to a full cluster compromise.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:kubernetes:kubernetes:*:*:*:*:*:*:*:* 1.6.0 (including) 1.15.0 (including)
cpe:2.3:a:kubernetes:kubernetes:*:*:*:*:*:*:*:* 1.16.0 (including) 1.16.13 (excluding)
cpe:2.3:a:kubernetes:kubernetes:*:*:*:*:*:*:*:* 1.17.0 (including) 1.17.9 (excluding)
cpe:2.3:a:kubernetes:kubernetes:*:*:*:*:*:*:*:* 1.18.0 (including) 1.18.6 (excluding)