openshift/machine-config-operator: /etc/kubernetes/kubeconfig is given incorrect privileges
Published Jun 2, 2021
7.0
HIGHCVSS 3.1
EPSS 0.22%
Description
An insecure modification flaw in the /etc/kubernetes/kubeconfig file was found in OpenShift. This flaw allows an attacker with access to a running container which mounts /etc/kubernetes or has local access to the node, to copy this kubeconfig file and attempt to add their own node to the OpenShift cluster. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability. This flaw affects versions before openshift4/ose-machine-config-operator v4.7.0-202105111858.p0.
Affected products
- Vendor n/a Product Openshift/machine-Config-Operator Defaultn/a
- Version UnspecifiedStatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| n/a | Openshift/machine-Config-Operator | n/a |
|
No data.
Red Hat OpenShift Container Platform 4
openshift4/ose-machine-config-rhel9-operator
Fix deferred
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat OpenShift Container Platform 4 | openshift4/ose-machine-config-rhel9-operator | Fix deferred | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
The kubeconfig file on the node is that of the bootstrap certificate. This means that to successfully exploit this vulnerability, the kubeconfig file must be taken and used within the first 24 hours of creation as it is created with a short expiration time. Otherwise, attempting to use the credentials after this time will result in the following: `Failed while requesting a signed certificate from the master: cannot create certificate signing request: Unauthorized` Further, if taken, the certificate signing request (CSR) of the joining rogue OpenShift node is not automatically approved by default. The node still needs to be approved through the use of the commands `oc get csr` and `oc adm certificate approve`.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
No CVSS v3.0 score for this CVE.
AV:L/AC:M/Au:N/C:P/I:P/A:P
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v5
- EPSS v2
- EPSS v3
- EPSS v4
Percentile over time
- EPSS v1
- EPSS v5
- EPSS v2
- EPSS v3
- EPSS v4
Table of values (10 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 0.22% (0.00218) | 11.06th | v5 (v2026.06.15) |
| Jun 15, 2026 | 0.22% (0.00218) | 12.10th | v5 (v2026.06.15) |
| Mar 17, 2025 | 0.04% (0.00041) | 9.72th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.04% (0.00044) | 14.58th | v3 (v2023.03.01) |
| May 25, 2024 | 0.04% (0.00044) | 12.27th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.04% (0.00044) | 10.26th | v3 (v2023.03.01) |
| Mar 6, 2023 | 0.89% (0.00885) | 27.89th | v2 (v2022.01.01) |
| Jan 6, 2022 | 1.84% (0.01840) | 47.32th | v1 |
| Jan 5, 2022 | 0.42% (0.00416) | 26.65th | v5 (v2026.06.15) |
| Jun 3, 2021 | 0.42% (0.00416) | 0.00th | v1 |
References (4)
- https://access.redhat.com/security/cve/CVE-2020-35514 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1914714 x_refsource_MISCIssue TrackingVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2020-35514
- https://www.cve.org/CVERecord?id=CVE-2020-35514
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2020-35514 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1914714 | x_refsource_MISCIssue TrackingVendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2020-35514 | ||
| https://www.cve.org/CVERecord?id=CVE-2020-35514 |
Change history (0)
No recorded changes yet.