Permissions, Privileges, and Access Controls in Kubernetes - CVE-2020-8559

 

Permissions, Privileges, and Access Controls in Kubernetes - CVE-2020-8559

Published: July 22, 2020 / Updated: September 4, 2020


Vulnerability identifier: #VU34130
CSH Severity: Medium
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N]
CVE-ID: CVE-2020-8559
CWE-ID: CWE-264
Exploitation vector: Remote access
Exploit availability: Public exploit is available

Vulnerability details

The vulnerability allows a remote privileged user to execute arbitrary code.

The Kubernetes kube-apiserver in versions v1.6-v1.15, and versions prior to v1.16.13, v1.17.9 and v1.18.6 are vulnerable to an unvalidated redirect on proxied upgrade requests that could allow an attacker to escalate privileges from a node compromise to a full cluster compromise.


Affected software

Kubernetes
Migration Toolkit for Containers
Red Hat OpenShift Container Platform
Consul
atomic-openshift (Red Hat package)
openshift-ansible (Red Hat package)
atomic-openshift-cluster-autoscaler (Red Hat package)
golang-github-prometheus-alertmanager (Red Hat package)
atomic-openshift-service-idler (Red Hat package)
atomic-openshift-metrics-server (Red Hat package)
atomic-openshift-node-problem-detector (Red Hat package)
openshift-enterprise-autoheal (Red Hat package)
atomic-openshift-web-console (Red Hat package)
atomic-openshift-descheduler (Red Hat package)
openshift-enterprise-cluster-capacity (Red Hat package)
golang-github-openshift-oauth-proxy (Red Hat package)
golang-github-prometheus-node_exporter (Red Hat package)
atomic-enterprise-service-catalog (Red Hat package)
golang-github-prometheus-prometheus (Red Hat package)
atomic-openshift-dockerregistry (Red Hat package)
openshift-kuryr (Red Hat package)
openshift (Red Hat package)
IBM Cloud Pak for Watson AIOps
IBM CICS TX Advanced
IBM CICS TX Standard

How to mitigate CVE-2020-8559

Install update from vendor's website.

Kubernetes - update to 1.18.6
Migration Toolkit for Containers - update to 1.7.4
Consul - update to 1.18.2
atomic-openshift (Red Hat package) - update to 3.11.346-1.git.0.ea10721.el7
openshift-ansible (Red Hat package) - update to 3.11.346-1.git.0.f65cc70.el7
atomic-openshift-cluster-autoscaler (Red Hat package) - update to 3.11.346-1.git.0.d16fdd8.el7
golang-github-prometheus-alertmanager (Red Hat package) - update to 3.11.346-1.git.0.c2f0036.el7
atomic-openshift-service-idler (Red Hat package) - update to 3.11.346-1.git.15.35bbcf7.el7
atomic-openshift-metrics-server (Red Hat package) - update to 3.11.346-1.git.53.f310e77.el7
atomic-openshift-node-problem-detector (Red Hat package) - update to 3.11.346-1.git.263.335bb76.el7
openshift-enterprise-autoheal (Red Hat package) - update to 3.11.346-1.git.218.08313c9.el7
atomic-openshift-web-console (Red Hat package) - update to 3.11.346-1.git.619.3bb8f35.el7
atomic-openshift-descheduler (Red Hat package) - update to 3.11.346-1.git.299.eda6813.el7
openshift-enterprise-cluster-capacity (Red Hat package) - update to 3.11.346-1.git.379.a389b99.el7
golang-github-openshift-oauth-proxy (Red Hat package) - update to 3.11.346-1.git.439.d3d1b1e.el7
golang-github-prometheus-node_exporter (Red Hat package) - update to 3.11.346-1.git.1062.c498733.el7
atomic-enterprise-service-catalog (Red Hat package) - update to 3.11.346-1.git.1675.f80310c.el7
golang-github-prometheus-prometheus (Red Hat package) - update to 3.11.346-1.git.5026.2eafa83.el7
atomic-openshift-dockerregistry (Red Hat package) - update to 3.11.346-1.git.481.1a70926.el7
openshift-kuryr (Red Hat package) - update to 3.11.346-1.git.1478.b99caab.el7
Red Hat OpenShift Container Platform - addressed in versions 3.11.343, 4.4.32, 4.5.21
openshift (Red Hat package) - addressed in versions 4.4.0-202012052258.p0.git.0.0fd57a4.el7, 4.4.0-202012052258.p0.git.0.0fd57a4.el8
IBM Cloud Pak for Watson AIOps - update to 4.8.1
IBM CICS TX Advanced - update to 11.1.0.0 ifix5
IBM CICS TX Standard - update to 11.1.0.0 ifix5

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins