PT-2020-6970 · Kubernetes+2 · Kubernetes Kube-Apiserver+3

Published

2019-08-13

·

Updated

2026-04-01

·

CVE-2020-8559

CVSS v2.0

8.3

High

VectorAV:N/AC:L/Au:M/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Kubernetes kube-apiserver versions v1.6 through v1.15 Kubernetes kube-apiserver versions prior to v1.16.13 Kubernetes kube-apiserver versions prior to v1.17.9 Kubernetes kube-apiserver versions prior to v1.18.6
Description The issue is related to an unvalidated redirect on proxied upgrade requests in the Kubernetes kube-apiserver. This could allow an attacker to escalate privileges from a node compromise to a full cluster compromise. The exploitation of this issue may enable a remote attacker to increase their privileges.
Recommendations For versions v1.6 through v1.15, update to a version after v1.15. For versions prior to v1.16.13, update to v1.16.13 or later. For versions prior to v1.17.9, update to v1.17.9 or later. For versions prior to v1.18.6, update to v1.18.6 or later. As a temporary workaround, consider restricting access to proxied upgrade requests until a patch is available.

Exploit

Fix

Open Redirect

Weakness Enumeration

Related Identifiers

ALT-PU-2019-2453
ALT-PU-2019-2454
ALT-PU-2020-2454
ALT-PU-2020-2462
BDU:2024-06031
CLEANSTART-2026-GI67088
CLEANSTART-2026-TC31671
CVE-2020-8559
ELSA-2020-5765
ELSA-2020-5766
ELSA-2020-5767
GHSA-33C5-9FX5-FVJM
GO-2024-2748
RHSA-2020:5363
RHSA-2021:0030

Affected Products

Alt Linux
Kubernetes
Kubernetes Kube-Apiserver
Red Os