The Kubernetes kube-controller-manager in versions v1.0-1.14, versions prior to v1.15.12, v1.16.9, v1.17.5, and version v1.18.0 are vulnerable to a Server Side Request Forgery (SSRF) that allows certain authorized users to leak up to 500 bytes of arbitrary information from unprotected endpoints within the master's host network (such as link-local or loopback services).
Metrics
Affected Vendors & Products
Fixes
Solution
No solution given by the vendor.
Workaround
Prior to upgrading, this vulnerability can be mitigated by adding endpoint protections on the master or restricting usage of the vulnerable volume types (for example by constraining usage with a PodSecurityPolicy or third-party admission controller such as Gatekeeper) and restricting StorageClass write permissions through RBAC.
References
History
No history.

Status: PUBLISHED
Assigner: kubernetes
Published:
Updated: 2024-09-16T18:39:58.006Z
Reserved: 2020-02-03T00:00:00
Link: CVE-2020-8555

No data.

Status : Modified
Published: 2020-06-05T17:15:11.640
Modified: 2024-11-21T05:39:01.533
Link: CVE-2020-8555


No data.