CVE-2020-8559

MEDIUM6.8EPSS 51.2%

Privilege Escalation in Kubernetes

發布日:2024/4/24修改日:2026/2/4
也稱為:GHSA-33c5-9fx5-fvjmCGA-wfgx-x98f-7jmqGO-2024-2748

描述

The Kubernetes kube-apiserver in versions v1.6-v1.15, and versions prior to v1.16.13, v1.17.9 and v1.18.7 are vulnerable to an unvalidated redirect on proxied upgrade requests that could allow an attacker to escalate privileges from a node compromise to a full cluster compromise.

受影響套件(5)

CVSS 分數

來源版本嚴重程度向量
osvCVSS 3.1MEDIUM6.8CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H

參考連結(11)