#VU94655 Time-of-check Time-of-use (TOCTOU) Race Condition in Kubernetes - CVE-2020-8562
Published: July 23, 2024
Kubernetes
Kubernetes
Description
The vulnerability allows a remote privileged user to gain access to potentially sensitive information.
The vulnerability exists due to a time-of-check time-of-use (TOCTOU) race condition flaw in the API Server proxy. A remote privileged user can send a specially-crafted request and exploit this vulnerability to gain access to private networks on the Kubernetes control plane components.