CVE-2020-8553: Kubernetes ingress-nginx Compromise of auth via subset/superset namespace names
The Kubernetes ingress-nginx component prior to version 0.28.0 allows a user with the ability to create namespaces and to read and create ingress objects to overwrite the password file of another ingress which uses nginx.ingress.kubernetes.io/auth-type: basic and which has a hyphenated namespace or secret name.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-8553?
CVE-2020-8553 is a vulnerability in the Kubernetes ingress-nginx component prior to version 0.28.0.
What is the severity of CVE-2020-8553?
CVE-2020-8553 has a severity score of 5.9 (medium).
How can CVE-2020-8553 be exploited?
CVE-2020-8553 can be exploited by a user with the ability to create namespaces and to read and create ingress objects to overwrite the password file of another ingress.
Which software versions are affected by CVE-2020-8553?
The Kubernetes ingress-nginx component versions prior to 0.28.0 are affected by CVE-2020-8553.
Is there a fix for CVE-2020-8553?
Yes, the fix for CVE-2020-8553 is to upgrade to version 0.28.0 or later of the Kubernetes ingress-nginx component.