Search Results (Refine Search)
- Keyword (text search): cpe:2.3:a:kubernetes:kubernetes:1.25.16:*:*:*:*:*:*:*
- CPE Name Search: true
Vuln ID | Summary | CVSS Severity |
---|---|---|
CVE-2020-8554 |
Kubernetes API server in all versions allow an attacker who is able to create a ClusterIP service and set the spec.externalIPs field, to intercept traffic to that IP address. Additionally, an attacker who is able to patch the status (which is considered a privileged operation and should not typically be granted to users) of a LoadBalancer service can set the status.loadBalancer.ingress.ip to similar effect. Published: January 21, 2021; 12:15:13 PM -0500 |
V4.0:(not available) V3.1: 5.0 MEDIUM V2.0: 6.0 MEDIUM |