CVE-2020-8561: stato di sfruttamento e disponibilità della patch
CVE-2020-8561 · CVSS 4.1 MEDIUM · EPSS 2%
A security issue was discovered in Kubernetes where actors that control the responses of MutatingWebhookConfiguration or ValidatingWebhookConfiguration requests are able to redirect kube-apiserver requests to private networks of the apiserver. If that user can view kube-apiserver logs when the log level is set to 10, they can view the redirected responses and headers in the logs.
CVE-2020-8561 viene sfruttato?
Non è nel catalogo CISA KEV.
EPSS stima la probabilità di sfruttamento nei prossimi 30 giorni al 2%.
Codice di exploit pubblico: nessuno trovato nelle fonti monitorate.
Quali prodotti e versioni sono interessati?
Nessun elenco di pacchetti interessati registrato qui.