Description
The Kubernetes kube-apiserver in versions v1.6-v1.15, and versions prior to v1.16.13, v1.17.9 and v1.18.6 are vulnerable to an unvalidated redirect on proxied upgrade requests that could allow an attacker to escalate privileges from a node compromise to a full cluster compromise.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-33c5-9fx5-fvjm | Privilege Escalation in Kubernetes |
References
History
No history.
Status: PUBLISHED
Assigner: kubernetes
Published:
Updated: 2024-09-16T17:58:15.587Z
Reserved: 2020-02-03T00:00:00.000Z
Link: CVE-2020-8559
No data.
Status : Modified
Published: 2020-07-22T14:15:16.517
Modified: 2024-11-21T05:39:01.920
Link: CVE-2020-8559
OpenCVE Enrichment
No data.
Weaknesses
Github GHSA