VDB
RHSA-2020%3A3184
RHSA-2020%3A3184
PUBLISHED
CVSS 5.400000095367432 MEDIUM
A flaw was found in Kubernetes that allows attackers on adjacent networks to reach services exposed on localhost ports, previously thought to be unreachable. This flaw allows an attacker to gain privileges or access confidential information for any services listening on localhost ports that are not protected by authentication.
Risk Scores
CVSS 3.1
5.400000095367432
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | openshift4/ose-hyperkube@sha256:f9bdfc3dab76dbe7b39892f97997a94e444acf37801a8a53592b55a05cef331a_s390x as a component of Red Hat OpenShift Container Platform 4.3 | * |
| Red Hat | openshift4/ose-hyperkube@sha256:96af3c6ba7ed5a52350cfeb1ebecce7bf39743eeeca872c4de3c962b23fbf81a_ppc64le as a component of Red Hat OpenShift Container Platform 4.3 | openshift4/ose-hyperkube@sha256:96af3c6ba7ed5a52350cfeb1ebecce7bf39743eeeca872c4de3c962b23fbf81a_ppc64le |
| Red Hat | openshift4/ose-hyperkube@sha256:e5446b29f5856c8547c4217c8a0aacbc0a9a6760ff39acb4ac70c19f4501bc90_amd64 as a component of Red Hat OpenShift Container Platform 4.3 | openshift4/ose-hyperkube@sha256:e5446b29f5856c8547c4217c8a0aacbc0a9a6760ff39acb4ac70c19f4501bc90_amd64 |
Timeline
- Aug 5, 2020 CVE Published
- Nov 21, 2025 CVE Updated
- May 1, 2026 Distribution Patch
- May 1, 2026 Distribution Patch
- May 1, 2026 Security Advisory
- May 1, 2026 Security Advisory
References
- https://access.redhat.com/errata/RHSA-2020:3184 advisory
- https://access.redhat.com/security/updates/classification/#moderate advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1843358 issue
- https://security.access.redhat.com/data/csaf/v2/advisories/2020/rhsa-2020_3184.json advisory
- https://access.redhat.com/security/cve/CVE-2020-8558 advisory
- https://www.cve.org/CVERecord?id=CVE-2020-8558 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2020-8558 advisory
- https://groups.google.com/g/kubernetes-security-announce/c/B1VegbBDMTE advisory