Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2020-8561

19
FAUCET Score

CVE-2020-8561 is a security vulnerability in Kubernetes that allows attackers controlling MutatingWebhookConfiguration or ValidatingWebhookConfiguration responses to redirect kube-apiserver requests to private networks. This medium severity vulnerability (CVSS 4.1) has a low impact on confidentiality, as redirected responses and headers can only be viewed in kube-apiserver logs if the log level is set to 10. There is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.

Impacted Technologies

VendorProductVersion(s)CPE
1.20.11CPE matchmatch criteria
cpe:2.3:a:kubernetes:kubernetes:1.20.11:-:*:*:*:*:*:*
1.21.5CPE matchmatch criteria
cpe:2.3:a:kubernetes:kubernetes:1.21.5:-:*:*:*:*:*:*
1.22.2CPE matchmatch criteria
cpe:2.3:a:kubernetes:kubernetes:1.22.2:-:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

4.1MEDIUM

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:N/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
HIGH
User Interaction
NONE
Scope
CHANGED
Confidentiality Impact
LOW
Integrity Impact
NONE
Availability Impact
NONE
Exploitability Score
2.3
Impact Score
1.4
CvssVersion
3.1

Exploit Intelligence

EPSS Score
2.10%
Probability of exploitation in next 30 days
EPSS Percentile
79.8%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0210 is in the 89th percentile among its peer group of 3,566 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (9)

boschpatch availablevia llm_extracted
View patch
microsoftpatch availablevia msrc
Product: cm1 kubernetes 1.22.6-1 on CBL Mariner 1.0Fixed in: 1.22.6-1
microsoftpatch availablevia msrc
Product: 19098-16820Fixed in: 1.22.6-1
mongodbpatch availablevia llm_extracted
View patch
github_advisoryworkaround availablevia nvd_reference
View patch
check_pointvendor investigatingvia llm_extracted
View patch
chromevendor investigatingvia llm_extracted
View patch
infiniflowvendor investigatingvia llm_extracted
View patch
vuevendor investigatingvia llm_extracted
View patch

Vendor Advisories (9)

goGHSA-74j8-88mm-7496medium

Confused Deputy in Kubernetes

Sep 21, 2021
redhatCVE-2020-8561Moderate

kubernetes: Webhook redirect in kube-apiserver

Sep 15, 2021
microsoft2021-Sep/CVE-2020-8561Moderate

Webhook redirect in kube-apiserver

Sep 14, 2021
chromellm-chrome-990047e90f5a7e6c

Webhook redirect in kube-apiserver

check_pointllm-check_point-ef26d5e110142cd5

Webhook redirect in kube-apiserver

mongodbllm-mongodb-acf627d188117924MEDIUM

Kubernetes webhook redirection vulnerability (CVE-2020-8561)

infiniflowllm-infiniflow-d9870bfcce9837fa

Webhook redirect in kube-apiserver

vuellm-vue-0ff7b28012ffdb79

Webhook redirect in kube-apiserver

boschllm-bosch-17d744f15669c9b5MEDIUM

Kubernetes webhook redirect vulnerability (CVE-2020-8561)

References

github.com / kubernetes/kubernetes/issues/104720
MitigationThird Party Advisory
groups.google.com / g/kubernetes-security-announce/c/RV2IhwcrQsY
Mailing ListMitigation
kubernetes.io / blog/2026/05/26/reconciling-unfixed-kubernetes-cves
security.netapp.com / advisory/ntap-20211014-0002
Third Party Advisory