Unprotected Alternate Channel in Kubelet - CVE-2020-8558
Published: February 13, 2025
Vulnerability details
The vulnerability allows an adjacent attacker to reach TCP and UDP services.
The vulnerability exists due to application does not properly control consumption of internal resources. An adjacent attacker can reach TCP and UDP services bound to 127.0.0.1 running on the node or in the node's network namespace. Such a service is generally thought to be reachable only by other processes on the same host, but due to this defeect, could be reachable by other hosts on the same LAN as the node, or by containers running on the same node as the service.
Affected software
openshift (Red Hat package)
machine-config-daemon (Red Hat package)
IBM Cloud Pak for Watson AIOps
How to mitigate CVE-2020-8558
openshift (Red Hat package) - addressed in versions 4.3.31-202007280738.p0.git.0.9884401.el7, 4.3.31-202007280738.p0.git.0.9884401.el8, 4.4.0-202007090832.p0.git.0.bc32fb1.el7, 4.4.0-202007090832.p0.git.0.bc32fb1.el8, 4.5.0-202007012112.p0.git.0.582d7fc.el7, 4.5.0-202007012112.p0.git.0.582d7fc.el8
machine-config-daemon (Red Hat package) - addressed in versions 4.4.0-202007092124.p0.git.2349.08d34d1.el8, 4.5.0-202007012112.p0.git.2527.d12c3da.el8
IBM Cloud Pak for Watson AIOps - update to 4.8.1
External References
Related Security Bulletins
- Unprotected Alternate Channel in Kubelet kube-proxy
- Multiple vulnerabilities in IBM Cloud Pak for AIOps
- Red Hat OpenShift Container Platform 4 update for machine-config-daemon and openshift
- Red Hat OpenShift Container Platform 4 update for machine-config-daemon and openshift
- Red Hat OpenShift Container Platform 4 update for openshift