PT-2021-12791 · Unknown+2 · Kubernetes+1

Javier Provecho

·

Published

2021-05-04

·

Updated

2026-06-06

·

CVE-2020-8562

CVSS v2.0

3.5

Low

VectorAV:N/AC:M/Au:S/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions: Kubernetes versions prior to a fixed version (no specific fixed version mentioned)
Description: The issue concerns a mitigation attempt by Kubernetes to prevent proxied connections from accessing link-local or localhost networks. However, a user may be able to bypass the proxy IP restriction and access private networks on the control plane if a non-standard DNS server returns different non-cached responses. This can be exploited through various methods, including proxying on addresses outside the cluster, SSRF through fake nodes, and exploiting a TOCTOU vulnerability. The estimated number of potentially affected devices is not specified.
Recommendations: As a temporary workaround, consider disabling the kubectl proxy function until a patch is available. Restrict access to the Kubernetes API Server to minimize the risk of exploitation. Avoid using the status field in Pod manifests to proxy requests to arbitrary addresses. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Time Of Check To Time Of Use

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2021-2101
ALT-PU-2022-1245
CVE-2020-8562
GHSA-QH36-44JV-C8XJ
GO-2022-0617
OPENSUSE-SU-2025:15424-1

Affected Products

Alt Linux
Kubernetes