VDB

CVE-2020-8557

CVE-2020-8557 REJECTED

The Kubernetes kubelet component in versions 1.1-1.16.12, 1.17.0-1.17.8 and 1.18.0-1.18.5 do not account for disk usage by a pod which writes to its own /etc/hosts file. The /etc/hosts file mounted in a pod by kubelet is not included by the kubelet eviction manager when calculating ephemeral storage usage by a pod. If a pod writes a large amount of data to the /etc/hosts file, it could fill the storage space of the node and cause the node to fail.

EPSS 0.11% · 29.2th percentile

Risk Scores

EPSS Score
0.11%
29.2th percentile

Affected Products

VendorProductVersions
Ubuntu:24.04:LTSkubernetes0, 1.0
Ubuntu:22.04:LTSkubernetes0, 1.0
Ubuntu:Pro:20.04:LTSkubernetes1.0, 0

Exploit Intelligence

…and 13 more exploits

Timeline

  • CVE Published
  • Jul 22, 2020 PoC Published
  • Apr 14, 2021 EPSS Score
  • Jun 23, 2021 EPSS Score
  • Aug 24, 2021 EPSS Score
  • Oct 26, 2021 EPSS Score
  • Jan 6, 2022 EPSS Score
  • Feb 4, 2022 EPSS Score
  • Feb 28, 2022 EPSS Score
  • Apr 1, 2022 EPSS Score
  • May 1, 2022 EPSS Score
  • Jul 3, 2022 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›