CVE-2020-8554: Kubernetes man in the middle using LoadBalancer or ExternalIPs

Published Oct 23, 2020
·
Updated

A flaw was found in kubernetes. If a potential attacker can already create or edit services and pods, then they may be able to intercept traffic from other pods (or nodes) in the cluster.

Other sources

A security issue was discovered with Kubernetes affecting multitenant clusters. If a potential attacker can already create or edit services and pods, then they may be able to intercept traffic from other pods (or nodes) in the cluster.

Red Hat

Kubernetes API server in all versions allow an attacker who is able to create a ClusterIP service and set the spec.externalIPs field, to intercept traffic to that IP address. Additionally, an attacker who is able to patch the status (which is considered a privileged operation and should not typically be granted to users) of a LoadBalancer service can set the status.loadBalancer.ingress.ip to similar effect.

Affected Software

5 affected componentsFixes available
redhat/atomic-openshift<0:3.11.374-1.git.0.ebd3ee9.el7
0:3.11.374-1.git.0.ebd3ee9.el7
Kubernetes kubernetes
Oracle Communications Cloud Native Core Network Slice Selection Function=1.2.1
Oracle Communications Cloud Native Core Policy=1.15.0
Oracle Communications Cloud Native Core Service Communication Proxy=1.14.0

Remediation

Information

ExternalIP addresses ranges can be configured as described below. OCP 4 is secure by default, though cluster-admins can whitelist externalIP addresses as needed. OCP 3.11 can be secured by changing `externalIPNetworkCIDR` to "0.0.0.0/32", which blocks all externalIP address values. https://docs.openshift.com/container-platform/4.6/networking/configuring_ingress_cluster_traffic/configuring-externalip.html https://docs.openshift.com/container-platform/3.11/admin_guide/tcp_ingress_external_ports.html#service-externalip Users can check if they have permission to patch the Status of a LoadBalancer Service with the command: `kubectl auth can-i patch service --subresource=status`. In OCP, by default only cluster-admins are granted this permission.

Event History

Oct 23, 2020
Data Sourced
via Red Hat·05:03 PM
DescriptionSeverityAffected Software
Dec 7, 2020
CVE Published
12:00 AM
Jan 21, 2021
CVE Published
via MITRE·05:09 PM
Data Sourced
via MITRE·05:09 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:15 PM
RemedyDescriptionSeverityWeaknessAffected Software

Parent advisories

This vulnerability appears in the following advisories.

Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the vulnerability ID for this flaw in Kubernetes?

The vulnerability ID is CVE-2020-8554.

2

What is the severity of CVE-2020-8554?

The severity of CVE-2020-8554 is medium (6.3).

3

How can an attacker exploit CVE-2020-8554?

An attacker can exploit CVE-2020-8554 by creating a ClusterIP service and setting the spec.externalIPs field to intercept traffic.

4

Which versions of Kubernetes are affected by CVE-2020-8554?

All versions of Kubernetes are affected by CVE-2020-8554.

5

Where can I find more information about CVE-2020-8554?

You can find more information about CVE-2020-8554 in the references provided.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203