CVE-2020-8554: Kubernetes man in the middle using LoadBalancer or ExternalIPs

Published Oct 23, 2020
·
Updated

A flaw was found in kubernetes. If a potential attacker can already create or edit services and pods, then they may be able to intercept traffic from other pods (or nodes) in the cluster.

Other sources

A security issue was discovered with Kubernetes affecting multitenant clusters. If a potential attacker can already create or edit services and pods, then they may be able to intercept traffic from other pods (or nodes) in the cluster.

Red Hat

Kubernetes API server in all versions allow an attacker who is able to create a ClusterIP service and set the spec.externalIPs field, to intercept traffic to that IP address. Additionally, an attacker who is able to patch the status (which is considered a privileged operation and should not typically be granted to users) of a LoadBalancer service can set the status.loadBalancer.ingress.ip to similar effect.

Affected Software

6 affected componentsFixes available
redhat/atomic-openshift<0:3.11.374-1.git.0.ebd3ee9.el7
0:3.11.374-1.git.0.ebd3ee9.el7
Kubernetes kubernetes
Oracle Communications Cloud Native Core Network Slice Selection Function=1.2.1
Oracle Communications Cloud Native Core Policy=1.15.0
Oracle Communications Cloud Native Core Service Communication Proxy=1.14.0
IBM Netezza Software<=11.3.0.3-IF2

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade redhat/atomic-openshift to a version that resolves this vulnerability.

    Fixed in 0:3.11.374-1.git.0.ebd3ee9.el7
  2. Configuration

    In OCP 3.11, change externalIPNetworkCIDR to "0.0.0.0/32" to block all externalIP address values and prevent traffic interception via externalIPs.

    OpenShift Container Platform (OCP) 3.11 externalIPNetworkCIDR = 0.0.0.0/32
  3. Configuration

    In OCP 4, ensure cluster-admins only whitelist specific externalIP addresses as needed (default is secure) to reduce risk of traffic interception via externalIPs.

    OpenShift Container Platform (OCP) 4 externalIPNetworkCIDR = allowed externalIP addresses (whitelist)
  4. Compensating control

    Check whether you are allowed to patch the status of a LoadBalancer service using: kubectl auth can-i patch service --subresource=status. If not required, remove/grant-less this privileged permission to prevent setting status.loadBalancer.ingress.ip to attacker-controlled values.

Event History

Oct 23, 2020
Data Sourced
via Red Hat·05:03 PM
DescriptionSeverityAffected Software
Dec 7, 2020
CVE Published
12:00 AM
Jan 21, 2021
CVE Published
via MITRE·05:09 PM
Data Sourced
via MITRE·05:09 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Aug 20, 2026
Data Sourced
via IBM·12:00 AM
DescriptionAffected Software

Parent advisories

This vulnerability appears in the following advisories.

Frequently Asked Questions

1

What is the vulnerability ID for this flaw in Kubernetes?

The vulnerability ID is CVE-2020-8554.

2

What is the severity of CVE-2020-8554?

The severity of CVE-2020-8554 is medium (6.3).

3

How can an attacker exploit CVE-2020-8554?

An attacker can exploit CVE-2020-8554 by creating a ClusterIP service and setting the spec.externalIPs field to intercept traffic.

4

Which versions of Kubernetes are affected by CVE-2020-8554?

All versions of Kubernetes are affected by CVE-2020-8554.

5

Where can I find more information about CVE-2020-8554?

You can find more information about CVE-2020-8554 in the references provided.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203