Advisory Database
  • Advisories
  • Dependency Scanning
  1. golang
  2. ›
  3. github.com/kubernetes/kube-proxy
  4. ›
  5. CVE-2020-8558

CVE-2020-8558: Improper Authentication

July 27, 2020 (updated July 29, 2020)

kube-proxy was found to contain a security issue which allows adjacent hosts to reach TCP and UDP services bound to localhost running on the node or in the node’s network namespace. Such a service is generally thought to be reachable only by other processes on the same host, but due to this defeect, could be reachable by other hosts on the same LAN as the node, or by containers running on the same node as the service.

References

  • nvd.nist.gov/vuln/detail/CVE-2020-8558

Code Behaviors & Features

Detect and mitigate CVE-2020-8558 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions starting from 1.1.0 up to 1.16.10, all versions starting from 1.17.0 up to 1.17.6, all versions starting from 1.18.0 up to 1.18.3

Fixed versions

  • v1.16.11-rc.0
  • v1.17.7-rc.0
  • v1.18.4-rc.0

Solution

Upgrade to versions 1.16.11-rc.0, 1.17.7-rc.0, 1.18.4-rc.0 or above. *Note*: 1.16.11-rc.0, 1.17.7-rc.0, and 1.18.4-rc.0 may be unstable versions. Use caution.

Impact 8.8 HIGH

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Learn more about CVSS

Weakness

  • CWE-287: Improper Authentication

Source file

go/github.com/kubernetes/kube-proxy/CVE-2020-8558.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Wed, 14 May 2025 12:16:04 +0000.