CVE-2020-8554 is a medium-severity vulnerability affecting all versions of Kubernetes, allowing an attacker to intercept traffic by manipulating ClusterIP or LoadBalancer service configurations. This man-in-the-middle attack requires specific privileges, such as the ability to create services with externalIPs or patch LoadBalancer service statuses. The vulnerability has a CVSS score of 5.0 (Medium) due to its network attack vector and high attack complexity, potentially leading to limited impact on confidentiality, integrity, and availability. While there is no known active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), the CVE has garnered significant community discussion and media coverage, indicating awareness and concern within the cybersecurity community.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:a:kubernetes:kubernetes:*:*:*:*:*:*:*:* | ||
1.2.1CPE matchmatch criteria | cpe:2.3:a:oracle:communications_cloud_native_core_network_slice_selection_function:1.2.1:*:*:*:*:*:*:* | ||
1.15.0CPE matchmatch criteria | cpe:2.3:a:oracle:communications_cloud_native_core_policy:1.15.0:*:*:*:*:*:*:* | ||
1.14.0CPE matchmatch criteria | cpe:2.3:a:oracle:communications_cloud_native_core_service_communication_proxy:1.14.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
CVE-2020-8554
Jun 11, 2024Unverified Ownership in Kubernetes
Feb 8, 2022The Kubernetes project recently discovered a new security vulnerability, CVE-2020-8554, that might allow an attacker who has obtained permissions to create a Kubernetes Service of type LoadBalancer or ClusterIP to intercept network traffic originating from other Pods in the cluster.
Dec 22, 2021Kubernetes Service Traffic Interception Vulnerability
Dec 22, 2021Kubernetes man in the middle using LoadBalancer or ExternalIPs
Jan 12, 2021kubernetes: MITM using LoadBalancer or ExternalIPs
Dec 7, 2020Kubernetes Service ExternalIPs Traffic Interception
Jan 1, 2020Man in the middle using LoadBalancer or ExternalIPs
Man in the middle using LoadBalancer or ExternalIPs
Man in the middle using LoadBalancer or ExternalIPs
Man in the middle using LoadBalancer or ExternalIPs