CVE-2020-8558

Improper Authentication in go/github.com/kubernetes/kube-proxy

Identifiers

CVE-2020-8558

Package Slug

go/github.com/kubernetes/kube-proxy

Vulnerability

Improper Authentication

Description

kube-proxy was found to contain a security issue which allows adjacent hosts to reach TCP and UDP services bound to localhost running on the node or in the node's network namespace. Such a service is generally thought to be reachable only by other processes on the same host, but due to this defeect, could be reachable by other hosts on the same LAN as the node, or by containers running on the same node as the service.

Affected Versions

All versions starting from 1.1.0 up to 1.16.10, all versions starting from 1.17.0 up to 1.17.6, all versions starting from 1.18.0 up to 1.18.3

Solution

Upgrade to versions 1.16.11-rc.0, 1.17.7-rc.0, 1.18.4-rc.0 or above. Note: 1.16.11-rc.0, 1.17.7-rc.0, and 1.18.4-rc.0 may be unstable versions. Use caution.

Last Modified

2020-07-31

source