Database/Container, Kubernetes & orchestration
Kubernetes (kube-apiserver): Any user who can create a Service with externalIPs (or patch LB status) intercepts cluster
CVE-2020-8554Container, Kubernetes & orchestrationcurated
Impact
Any user who can create a Service with externalIPs (or patch LB status) intercepts cluster traffic to that IP; MITM
Who can reach it
Cluster user with namespace access
What to do
No upstream code fix; deploy an admission policy denying externalIPs and status.loadBalancer patches for tenants
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.