VDB
RHSA-2020%3A2441
RHSA-2020%3A2441
PUBLISHED
CVSS 6.300000190734863 MEDIUM
A server side request forgery (SSRF) flaw was found in Kubernetes. The kube-controller-manager allows authorized users with the ability to create StorageClasses or certain Volume types to leak up to 500 bytes of arbitrary information from the master's host network. This can include secrets from the kube-apiserver through the unauthenticated localhost port (if enabled).
Risk Scores
CVSS 3.1
6.300000190734863
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | openshift4/ose-hyperkube@sha256:d196b0a4f412f63720e360957433b6daf48c88f6f23796f81443e01f86218a19_amd64 as a component of Red Hat OpenShift Container Platform 4.3 | openshift4/ose-hyperkube@sha256:d196b0a4f412f63720e360957433b6daf48c88f6f23796f81443e01f86218a19_amd64 |
| Red Hat | openshift4/ose-hyperkube@sha256:2d8d0beae7c6ac6eea010224d3df5b32477a1ba87ee345745698a0fcd3a7cc83_ppc64le as a component of Red Hat OpenShift Container Platform 4.3 | * |
| Red Hat | openshift4/ose-hyperkube@sha256:50eb07078ebeb62e620e64c871803776dd665decc0b5ad5be4e39a6caf97e9e1_s390x as a component of Red Hat OpenShift Container Platform 4.3 | openshift4/ose-hyperkube@sha256:50eb07078ebeb62e620e64c871803776dd665decc0b5ad5be4e39a6caf97e9e1_s390x |
Timeline
- Jun 17, 2020 CVE Published
- Nov 21, 2025 CVE Updated
- May 1, 2026 Distribution Patch
- May 1, 2026 Distribution Patch
- May 1, 2026 Security Advisory
- May 1, 2026 Security Advisory
References
- https://access.redhat.com/errata/RHSA-2020:2441 advisory
- https://access.redhat.com/security/updates/classification/#moderate advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1821583 issue
- https://security.access.redhat.com/data/csaf/v2/advisories/2020/rhsa-2020_2441.json advisory
- https://access.redhat.com/security/cve/CVE-2020-8555 advisory
- https://www.cve.org/CVERecord?id=CVE-2020-8555 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2020-8555 advisory
- https://groups.google.com/forum/#!topic/kubernetes-security-announce/kEK27tqqs30 advisory