VDB

DEBIAN-CVE-2020-8554

DEBIAN-CVE-2020-8554 PUBLISHED CVSS 5 MEDIUM

Kubernetes API server in all versions allow an attacker who is able to create a ClusterIP service and set the spec.externalIPs field, to intercept traffic to that IP address. Additionally, an attacker who is able to patch the status (which is considered a privileged operation and should not typically be granted to users) of a LoadBalancer service can set the status.loadBalancer.ingress.ip to similar effect.

Risk Scores

CVSS v3.1
5
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L

Affected Products

VendorProductVersions
Debian:13kubernetes0, 0, 0
Debian:14kubernetes0, 0, 0

Timeline

  • Jan 21, 2021 CVE Published
  • Apr 28, 2026 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›