VDB

RHSA-2020%3A2441

RHSA-2020%3A2441 PUBLISHED CVSS 6.300000190734863 MEDIUM

A server side request forgery (SSRF) flaw was found in Kubernetes. The kube-controller-manager allows authorized users with the ability to create StorageClasses or certain Volume types to leak up to 500 bytes of arbitrary information from the master's host network. This can include secrets from the kube-apiserver through the unauthenticated localhost port (if enabled).

Risk Scores

CVSS 3.1
6.300000190734863
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N

Affected Products

VendorProductVersions
Red Hatopenshift4/ose-hyperkube@sha256:d196b0a4f412f63720e360957433b6daf48c88f6f23796f81443e01f86218a19_amd64 as a component of Red Hat OpenShift Container Platform 4.3openshift4/ose-hyperkube@sha256:d196b0a4f412f63720e360957433b6daf48c88f6f23796f81443e01f86218a19_amd64
Red Hatopenshift4/ose-hyperkube@sha256:2d8d0beae7c6ac6eea010224d3df5b32477a1ba87ee345745698a0fcd3a7cc83_ppc64le as a component of Red Hat OpenShift Container Platform 4.3*
Red Hatopenshift4/ose-hyperkube@sha256:50eb07078ebeb62e620e64c871803776dd665decc0b5ad5be4e39a6caf97e9e1_s390x as a component of Red Hat OpenShift Container Platform 4.3openshift4/ose-hyperkube@sha256:50eb07078ebeb62e620e64c871803776dd665decc0b5ad5be4e39a6caf97e9e1_s390x

Timeline

  • Jun 17, 2020 CVE Published
  • Nov 21, 2025 CVE Updated
  • May 1, 2026 Distribution Patch
  • May 1, 2026 Distribution Patch
  • May 1, 2026 Security Advisory
  • May 1, 2026 Security Advisory
Open in Interactive Console →
$ Console Community · 100/wk Open console ›