CVE-2020-8554: stato di sfruttamento e disponibilità della patch
CVE-2020-8554 · CVSS 6.3 MEDIUM · EPSS 9%
Kubernetes API server in all versions allow an attacker who is able to create a ClusterIP service and set the spec.externalIPs field, to intercept traffic to that IP address. Additionally, an attacker who is able to patch the status (which is considered a privileged operation and should not typically be granted to users) of a LoadBalancer service can set the status.loadBalancer.ingress.ip to similar effect.
CVE-2020-8554 viene sfruttato?
Non è nel catalogo CISA KEV.
EPSS stima la probabilità di sfruttamento nei prossimi 30 giorni al 9%.
Codice di exploit pubblico: nessuno trovato nelle fonti monitorate.
Quali prodotti e versioni sono interessati?
Nessun elenco di pacchetti interessati registrato qui.