Kubernetes man in the middle using LoadBalancer or ExternalIPs
Published Jan 21, 2021
6.3
MEDIUMCVSS 3.1
EPSS 9.27%
Description
Kubernetes API server in all versions allow an attacker who is able to create a ClusterIP service and set the spec.externalIPs field, to intercept traffic to that IP address. Additionally, an attacker who is able to patch the status (which is considered a privileged operation and should not typically be granted to users) of a LoadBalancer service can set the status.loadBalancer.ingress.ip to similar effect.
Affected products
-
- Version 0StatusaffectedConstraints<*
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Kubernetes | Kubernetes | n/a |
|
Configuration 1
- n/a
Configuration 2
- 1.2.1
- 1.15.0
- 1.14.0
No data.
Red Hat OpenShift Container Platform 3.11
atomic-openshift-0:3.11.374-1.git.0.ebd3ee9.el7
Fixed · RHSA-2021:0079
Red Hat OpenShift Container Platform 4
openshift
Not affected
Red Hat Storage 3
heketi
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat OpenShift Container Platform 3.11 | atomic-openshift-0:3.11.374-1.git.0.ebd3ee9.el7 | Fixed | RHSA-2021:0079 |
| Red Hat OpenShift Container Platform 4 | openshift | Not affected | n/a |
| Red Hat Storage 3 | heketi | Not affected | n/a |
k8s.io/kubernetes
Go
Introduced 0 Fixed not fixed
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| Go | k8s.io/kubernetes | 0 | not fixed |
Remediation
Vendor solution
To restrict the use of external IPs we are providing an admission webhook container: k8s.gcr.io/multitenancy/externalip-webhook:v1.0.0. The source code and deployment instructions are published at https://github.com/kubernetes-sigs/externalip-webhook.
Alternatively, external IPs can be restricted using OPA Gatekeeper. A sample ConstraintTemplate and Constraint can be found here: https://github.com/open-policy-agent/gatekeeper-library/tree/master/library/general/externalip.
Red Hat statement
OpenShift Container Platform (OCP) includes a builtin externalIP admission plugin, which restricts the use of Service eternalIPs to those configured by a cluster-admin. In OCP4 all externalIP ranges are disabled by default. In OCP 3.11, the default range is "0.0.0.0/0", which allows all IP addresses. The second attack vector, via patching the Status of a LoadBalancer Service, is not possible unless permission to patch service/status is granted. OCP does not grant this permission to users who are not cluster-admins. OCP 4 is not affected by this vulnerability as it is secure by default. OCP 3.11 is affected, however the vulnerability can be by mitigated by configuring the builtin externalIP admission plugin.
Red Hat mitigation
ExternalIP addresses ranges can be configured as described below. OCP 4 is secure by default, though cluster-admins can whitelist externalIP addresses as needed. OCP 3.11 can be secured by changing `externalIPNetworkCIDR` to "0.0.0.0/32", which blocks all externalIP address values. https://docs.openshift.com/container-platform/4.6/networking/configuring_ingress_cluster_traffic/configuring-externalip.html https://docs.openshift.com/container-platform/3.11/admin_guide/tcp_ingress_external_ports.html#service-externalip Users can check if they have permission to patch the Status of a LoadBalancer Service with the command: `kubectl auth can-i patch service --subresource=status`. In OCP, by default only cluster-admins are granted this permission.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L
1 other source (CVE.org) ▾
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
No CVSS v3.0 score for this CVE.
AV:N/AC:M/Au:S/C:P/I:P/A:P
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (44 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 9.27% (0.09274) | 95.22th | v5 (v2026.06.15) |
| Jun 15, 2026 | 9.27% (0.09274) | 94.70th | v5 (v2026.06.15) |
| Mar 10, 2026 | 24.78% (0.24784) | 96.05th | v4 (v2025.03.14) |
| Jan 26, 2026 | 30.95% (0.30948) | 96.60th | v4 (v2025.03.14) |
| Jan 4, 2026 | 24.78% (0.24784) | 95.95th | v4 (v2025.03.14) |
| Jan 1, 2026 | 30.66% (0.30663) | 96.59th | v4 (v2025.03.14) |
| Dec 4, 2025 | 24.78% (0.24784) | 95.93th | v4 (v2025.03.14) |
| Dec 1, 2025 | 30.66% (0.30663) | 96.56th | v4 (v2025.03.14) |
| Nov 21, 2025 | 24.78% (0.24784) | 95.92th | v4 (v2025.03.14) |
| Nov 18, 2025 | 20.33% (0.20327) | 95.12th | v4 (v2025.03.14) |
| Nov 4, 2025 | 24.78% (0.24784) | 95.91th | v4 (v2025.03.14) |
| Nov 1, 2025 | 30.66% (0.30663) | 96.53th | v4 (v2025.03.14) |
| Oct 4, 2025 | 24.78% (0.24784) | 95.95th | v4 (v2025.03.14) |
| Oct 1, 2025 | 30.66% (0.30663) | 96.58th | v4 (v2025.03.14) |
| Sep 4, 2025 | 24.78% (0.24784) | 95.95th | v4 (v2025.03.14) |
| Sep 1, 2025 | 30.66% (0.30663) | 96.59th | v4 (v2025.03.14) |
| Aug 4, 2025 | 24.78% (0.24784) | 95.91th | v4 (v2025.03.14) |
| Aug 1, 2025 | 30.66% (0.30663) | 96.57th | v4 (v2025.03.14) |
| Jul 5, 2025 | 24.78% (0.24784) | 95.88th | v4 (v2025.03.14) |
| Apr 16, 2025 | 30.66% (0.30663) | 96.39th | v4 (v2025.03.14) |
| Apr 13, 2025 | 24.78% (0.24784) | 95.72th | v4 (v2025.03.14) |
| Apr 12, 2025 | 30.66% (0.30663) | 96.35th | v4 (v2025.03.14) |
| Mar 30, 2025 | 24.78% (0.24784) | 95.69th | v4 (v2025.03.14) |
| Mar 29, 2025 | 61.17% (0.61174) | 97.59th | v4 (v2025.03.14) |
| Mar 28, 2025 | 24.78% (0.24784) | 95.69th | v4 (v2025.03.14) |
| Mar 27, 2025 | 60.30% (0.60298) | 98.02th | v4 (v2025.03.14) |
| Mar 22, 2025 | 24.78% (0.24784) | 95.70th | v4 (v2025.03.14) |
| Mar 21, 2025 | 30.66% (0.30663) | 96.35th | v4 (v2025.03.14) |
| Mar 20, 2025 | 24.78% (0.24784) | 95.71th | v4 (v2025.03.14) |
| Mar 19, 2025 | 60.30% (0.60298) | 98.05th | v4 (v2025.03.14) |
| Mar 17, 2025 | 24.78% (0.24784) | 95.68th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.33% (0.00325) | 71.61th | v3 (v2023.03.01) |
| Nov 8, 2023 | 0.24% (0.00238) | 61.69th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.13% (0.00131) | 46.18th | v3 (v2023.03.01) |
| Mar 6, 2023 | 15.38% (0.15380) | 95.99th | v2 (v2022.01.01) |
| Apr 20, 2022 | 15.38% (0.15380) | 95.64th | v2 (v2022.01.01) |
| Apr 1, 2022 | 18.12% (0.18119) | 95.94th | v2 (v2022.01.01) |
| Feb 8, 2022 | 18.12% (0.18119) | 93.48th | v2 (v2022.01.01) |
| Feb 4, 2022 | 14.00% (0.14004) | 90.93th | v2 (v2022.01.01) |
| Feb 3, 2022 | 7.04% (0.07038) | 83.71th | v1 |
| Jan 6, 2022 | 7.04% (0.07038) | 83.55th | v1 |
| Sep 1, 2021 | 7.04% (0.07038) | 91.20th | v1 |
| Jul 21, 2021 | 7.04% (0.07038) | 0.00th | v1 |
| Apr 14, 2021 | 6.21% (0.06208) | 0.00th | v1 |
References (21)
- https://access.redhat.com/security/cve/CVE-2020-8554 Vendor Advisory
- https://blog.champtar.fr/K8S_MITM_LoadBalancer_ExternalIPs/
- https://bugzilla.redhat.com/show_bug.cgi?id=1891051 Issue Tracking
- https://github.com/advisories/GHSA-j9wf-vvm6-4r9w Advisory
- https://github.com/kubernetes/kubernetes/issues/97076 x_refsource_MISCExploitThird Party Advisory
- https://github.com/kubernetes/kubernetes/issues/97110
- https://groups.google.com/g/kubernetes-security-announce/c/iZWsF9nbKE8 x_refsource_MISCMailing ListThird Party Advisory
- https://kubernetes.io/blog/2026/05/26/reconciling-unfixed-kubernetes-cves x_refsource_MISC
- https://lists.apache.org/thread.html/r0c76b3d0be348f788cd947054141de0229af00c540564711e828fd40%40%3Ccommits.druid.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/r0c76b3d0be348f788cd947054141de0229af00c540564711e828fd40@%3Ccommits.druid.apache.org%3E
- https://lists.apache.org/thread.html/r1975078e44d96f2a199aa90aa874b57a202eaf7f25f2fde6d1c44942%40%3Ccommits.druid.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/r1975078e44d96f2a199aa90aa874b57a202eaf7f25f2fde6d1c44942@%3Ccommits.druid.apache.org%3E
- https://lists.apache.org/thread.html/rcafa485d63550657f068775801aeb706b7a07140a8ebbdef822b3bb3%40%3Ccommits.druid.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/rcafa485d63550657f068775801aeb706b7a07140a8ebbdef822b3bb3@%3Ccommits.druid.apache.org%3E
- https://lists.apache.org/thread.html/rdb223e1b82e3d7d8e4eaddce8dd1ab87252e3935cc41c859f49767b6%40%3Ccommits.druid.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/rdb223e1b82e3d7d8e4eaddce8dd1ab87252e3935cc41c859f49767b6@%3Ccommits.druid.apache.org%3E
- https://nvd.nist.gov/vuln/detail/CVE-2020-8554
- https://www.cve.org/CVERecord?id=CVE-2020-8554
- https://www.oracle.com//security-alerts/cpujul2021.html x_refsource_MISCPatchThird Party Advisory
- https://www.oracle.com/security-alerts/cpuapr2022.html x_refsource_MISCPatchThird Party Advisory
- https://www.oracle.com/security-alerts/cpujan2022.html x_refsource_MISCPatchThird Party Advisory
Change history (0)
No recorded changes yet.