SB2020080526 - Red Hat OpenShift Container Platform 4 update for openshift



SB2020080526 - Red Hat OpenShift Container Platform 4 update for openshift

Published: August 5, 2020 Updated: April 24, 2025

Security Bulletin ID SB2020080526
Severity
Medium
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Adjecent network
Highest impact Data manipulation

Breakdown by Severity

Medium 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Unprotected Alternate Channel (CVE-ID: CVE-2020-8558)

The vulnerability allows an adjacent attacker to reach TCP and UDP services.

The vulnerability exists due to application does not properly control consumption of internal resources. An adjacent attacker can reach TCP and UDP services bound to 127.0.0.1 running on the node or in the node's network namespace. Such a service is generally thought to be reachable only by other processes on the same host, but due to this defeect, could be reachable by other hosts on the same LAN as the node, or by containers running on the same node as the service.


Remediation

Install update from vendor's website.