← Back to CVE List

CVE-2020-8554

Published: 2021-01-21T17:15Z
Last Modified: 2024-11-21T05:39Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
Kubernetes API server in all versions allow an attacker who is able to create a ClusterIP service and set the spec.externalIPs field, to intercept traffic to that IP address. Additionally, an attacker who is able to patch the status (which is considered a privileged operation and should not typically be granted to users) of a LoadBalancer service can set the status.loadBalancer.ingress.ip to similar effect. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt