Input validation error in Google Kubernetes Engine - CVE-2020-2121
Published: February 13, 2020
Vulnerability identifier: #VU25292
CSH Severity: High
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-2121
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to the affected software does not configure its YAML parser to prevent the instantiation of arbitrary types. A remote authenticated attacker can execute arbitrary code on the system.
Affected software
Google Kubernetes Engine
How to mitigate CVE-2020-2121
Install updates from vendor's website.
Google Kubernetes Engine - update to 0.8.1