CVE-2020-8554
MEDIUM 6.3EPSS 9.3%
Kubernetes API server in all versions allow an attacker who is able to create a ClusterIP service and set the spec.externalIPs field, to intercept traffic to that IP address. Additionally, an attacker who is able to patch the status (which is considered a privileged operation and should not typically be granted to users) of a LoadBalancer service can set the status.loadBalancer.ingress.ip to similar effect.
- CVSS v3.1
- 5.0 MEDIUM
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L - CVSS v3.1
- 6.3 MEDIUM
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L - CVSS v3.1
- 5.0 MEDIUM
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L - CVSS v2.0
- 6.0 MEDIUM
AV:N/AC:M/Au:S/C:P/I:P/A:P - EPSS
- 9.27% chance of exploitation in the next 30 days, 95th percentile
- Published
- 2021-01-21
- Updated
- 2026-06-01
Proof-of-concept exploits (5)
- kubernetes/kubernetes/issues/97076
- Dviejopomata/CVE-2020-85540★ · 2021-01-22
- alebedev87/gatekeeper-cve-2020-85540★ · 2021-02-09
- jrmurray000/CVE-2020-85541★ · 2021-02-07
- twistlock/k8s-cve-2020-8554-mitigations1★ · 2020-12-22