Permissions, Privileges, and Access Controls in Kubernetes - CVE-2020-8559
Published: July 22, 2020 / Updated: September 4, 2020
Vulnerability details
The vulnerability allows a remote privileged user to execute arbitrary code.
The Kubernetes kube-apiserver in versions v1.6-v1.15, and versions prior to v1.16.13, v1.17.9 and v1.18.6 are vulnerable to an unvalidated redirect on proxied upgrade requests that could allow an attacker to escalate privileges from a node compromise to a full cluster compromise.
Affected software
Migration Toolkit for Containers
Red Hat OpenShift Container Platform
Consul
atomic-openshift (Red Hat package)
openshift-ansible (Red Hat package)
atomic-openshift-cluster-autoscaler (Red Hat package)
golang-github-prometheus-alertmanager (Red Hat package)
atomic-openshift-service-idler (Red Hat package)
atomic-openshift-metrics-server (Red Hat package)
atomic-openshift-node-problem-detector (Red Hat package)
openshift-enterprise-autoheal (Red Hat package)
atomic-openshift-web-console (Red Hat package)
atomic-openshift-descheduler (Red Hat package)
openshift-enterprise-cluster-capacity (Red Hat package)
golang-github-openshift-oauth-proxy (Red Hat package)
golang-github-prometheus-node_exporter (Red Hat package)
atomic-enterprise-service-catalog (Red Hat package)
golang-github-prometheus-prometheus (Red Hat package)
atomic-openshift-dockerregistry (Red Hat package)
openshift-kuryr (Red Hat package)
openshift (Red Hat package)
IBM Cloud Pak for Watson AIOps
IBM CICS TX Advanced
IBM CICS TX Standard
How to mitigate CVE-2020-8559
Migration Toolkit for Containers - update to 1.7.4
Consul - update to 1.18.2
atomic-openshift (Red Hat package) - update to 3.11.346-1.git.0.ea10721.el7
openshift-ansible (Red Hat package) - update to 3.11.346-1.git.0.f65cc70.el7
atomic-openshift-cluster-autoscaler (Red Hat package) - update to 3.11.346-1.git.0.d16fdd8.el7
golang-github-prometheus-alertmanager (Red Hat package) - update to 3.11.346-1.git.0.c2f0036.el7
atomic-openshift-service-idler (Red Hat package) - update to 3.11.346-1.git.15.35bbcf7.el7
atomic-openshift-metrics-server (Red Hat package) - update to 3.11.346-1.git.53.f310e77.el7
atomic-openshift-node-problem-detector (Red Hat package) - update to 3.11.346-1.git.263.335bb76.el7
openshift-enterprise-autoheal (Red Hat package) - update to 3.11.346-1.git.218.08313c9.el7
atomic-openshift-web-console (Red Hat package) - update to 3.11.346-1.git.619.3bb8f35.el7
atomic-openshift-descheduler (Red Hat package) - update to 3.11.346-1.git.299.eda6813.el7
openshift-enterprise-cluster-capacity (Red Hat package) - update to 3.11.346-1.git.379.a389b99.el7
golang-github-openshift-oauth-proxy (Red Hat package) - update to 3.11.346-1.git.439.d3d1b1e.el7
golang-github-prometheus-node_exporter (Red Hat package) - update to 3.11.346-1.git.1062.c498733.el7
atomic-enterprise-service-catalog (Red Hat package) - update to 3.11.346-1.git.1675.f80310c.el7
golang-github-prometheus-prometheus (Red Hat package) - update to 3.11.346-1.git.5026.2eafa83.el7
atomic-openshift-dockerregistry (Red Hat package) - update to 3.11.346-1.git.481.1a70926.el7
openshift-kuryr (Red Hat package) - update to 3.11.346-1.git.1478.b99caab.el7
Red Hat OpenShift Container Platform - addressed in versions 3.11.343, 4.4.32, 4.5.21
openshift (Red Hat package) - addressed in versions 4.4.0-202012052258.p0.git.0.0fd57a4.el7, 4.4.0-202012052258.p0.git.0.0fd57a4.el8
IBM Cloud Pak for Watson AIOps - update to 4.8.1
IBM CICS TX Advanced - update to 11.1.0.0 ifix5
IBM CICS TX Standard - update to 11.1.0.0 ifix5
Links to Public Exploits and PoC-codes
External References
Related Security Bulletins
- Security restrictions bypass in Kubernetes
- Multiple vulnerabilities in Red Hat OpenShift Container Platform
- Multiple vulnerabilitis in OpenShift Container Platform
- Security restrictions bypass in OpenShift Container Platform
- Multiple vulnerabilities in Migration Toolkit for Containers (MTC) 1.7
- Multiple vulnerabilities in IBM CICS TX Advanced
- Multiple vulnerabilities in IBM CICS TX Standard
- Multiple vulnerabilities in HashiCorp Consul
- Multiple vulnerabilities in IBM Cloud Pak for AIOps