Kubernetes node setting allows for neighboring hosts to bypass localhost boundary
Published Jul 27, 2020
8.8
HIGHCVSS 3.1
EPSS 3.60%
Description
The Kubelet and kube-proxy components in versions 1.1.0-1.16.10, 1.17.0-1.17.6, and 1.18.0-1.18.3 were found to contain a security issue which allows adjacent hosts to reach TCP and UDP services bound to 127.0.0.1 running on the node or in the node's network namespace. Such a service is generally thought to be reachable only by other processes on the same host, but due to this defeect, could be reachable by other hosts on the same LAN as the node, or by containers running on the same node as the service.
Affected products
-
- Version 1.1StatusaffectedConstraints-
- Version 1.10StatusaffectedConstraints-
- Version 1.11StatusaffectedConstraints-
- Version 1.12StatusaffectedConstraints-
- Version 1.13StatusaffectedConstraints-
- Version 1.14StatusaffectedConstraints-
- Version 1.15StatusaffectedConstraints-
- Version 1.2StatusaffectedConstraints-
- Version 1.3StatusaffectedConstraints-
- Version 1.4StatusaffectedConstraints-
- Version 1.5StatusaffectedConstraints-
- Version 1.6StatusaffectedConstraints-
- Version 1.7StatusaffectedConstraints-
- Version 1.8StatusaffectedConstraints-
- Version 1.9StatusaffectedConstraints-
- Version prior to 1.16.11StatusaffectedConstraints-
- Version prior to 1.17.7StatusaffectedConstraints-
- Version prior to 1.18.4StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Kubernetes | Kubernetes | n/a |
|
- ≥ 1.1.0 · ≤ 1.16.10
- ≥ 1.17.0 · ≤ 1.17.6
- ≥ 1.18.0 · ≤ 1.18.3
No data.
Red Hat OpenShift Container Platform 3.11
atomic-openshift-0:3.11.248-1.git.0.92ee8ac.el7
Fixed · RHSA-2020:2992
Red Hat OpenShift Container Platform 4.3
openshift-0:4.3.31-202007280738.p0.git.0.9884401.el7
Fixed · RHSA-2020:3183
Red Hat OpenShift Container Platform 4.3
openshift4/ose-hyperkube:v4.3.31-202007272153.p0
Fixed · RHSA-2020:3184
Red Hat OpenShift Container Platform 4.4
openshift-0:4.4.0-202007090832.p0.git.0.bc32fb1.el7
Fixed · RHSA-2020:2927
Red Hat OpenShift Container Platform 4.4
openshift4/ose-hyperkube:v4.4.0-202007120152.p0
Fixed · RHSA-2020:2926
Red Hat OpenShift Container Platform 4.5
openshift-0:4.5.0-202007012112.p0.git.0.582d7fc.el7
Fixed · RHSA-2020:2413
Red Hat OpenShift Container Platform 4.5
openshift4/ose-hyperkube:v4.5.0-202007100518.p0
Fixed · RHSA-2020:2412
Red Hat Storage 3
heketi
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat OpenShift Container Platform 3.11 | atomic-openshift-0:3.11.248-1.git.0.92ee8ac.el7 | Fixed | RHSA-2020:2992 |
| Red Hat OpenShift Container Platform 4.3 | openshift-0:4.3.31-202007280738.p0.git.0.9884401.el7 | Fixed | RHSA-2020:3183 |
| Red Hat OpenShift Container Platform 4.3 | openshift4/ose-hyperkube:v4.3.31-202007272153.p0 | Fixed | RHSA-2020:3184 |
| Red Hat OpenShift Container Platform 4.4 | openshift-0:4.4.0-202007090832.p0.git.0.bc32fb1.el7 | Fixed | RHSA-2020:2927 |
| Red Hat OpenShift Container Platform 4.4 | openshift4/ose-hyperkube:v4.4.0-202007120152.p0 | Fixed | RHSA-2020:2926 |
| Red Hat OpenShift Container Platform 4.5 | openshift-0:4.5.0-202007012112.p0.git.0.582d7fc.el7 | Fixed | RHSA-2020:2413 |
| Red Hat OpenShift Container Platform 4.5 | openshift4/ose-hyperkube:v4.5.0-202007100518.p0 | Fixed | RHSA-2020:2412 |
| Red Hat Storage 3 | heketi | Not affected | n/a |
k8s.io/kubernetes
Go
Introduced 1.18.0 Fixed 1.18.4k8s.io/kubernetes
Go
Introduced 1.17.0 Fixed 1.17.7k8s.io/kubernetes
Go
Introduced 0 Fixed 1.16.11
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| Go | k8s.io/kubernetes | 1.18.0 | 1.18.4 |
| Go | k8s.io/kubernetes | 1.17.0 | 1.17.7 |
| Go | k8s.io/kubernetes | 0 | 1.16.11 |
Remediation
Red Hat statement
OpenShift Container Platform does not expose the API server on a localhost port without authentication. The only service exposed on a localhost port not protected by authentication is Metrics, which exposes some cluster metadata.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
1 other source (CVE.org) ▾
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
No CVSS v3.0 score for this CVE.
AV:A/AC:L/Au:N/C:P/I:P/A:P
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 4, 2026.
Score over time
2021-2026- EPSS v1
- EPSS v5
- EPSS v2
- EPSS v3
- EPSS v4
Percentile over time
- EPSS v1
- EPSS v5
- EPSS v2
- EPSS v3
- EPSS v4
Table of values (24 key points)
Flat stretches are collapsed. Showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 4, 2026 | 3.60% (0.03597) | 89.10th | v5 (v2026.06.15) |
| Jun 15, 2026 | 3.60% (0.03597) | 87.93th | v5 (v2026.06.15) |
| May 27, 2026 | 20.15% (0.20149) | 95.58th | v4 (v2025.03.14) |
| May 22, 2026 | 21.49% (0.21485) | 95.79th | v4 (v2025.03.14) |
| Mar 7, 2026 | 20.15% (0.20149) | 95.38th | v4 (v2025.03.14) |
| Feb 22, 2026 | 21.49% (0.21485) | 95.59th | v4 (v2025.03.14) |
| Feb 18, 2026 | 20.15% (0.20149) | 95.35th | v4 (v2025.03.14) |
| Nov 21, 2025 | 24.21% (0.24206) | 95.85th | v4 (v2025.03.14) |
| Nov 18, 2025 | 15.11% (0.15113) | 93.98th | v4 (v2025.03.14) |
| Mar 30, 2025 | 25.12% (0.25123) | 95.72th | v4 (v2025.03.14) |
| Mar 29, 2025 | 34.77% (0.34768) | 95.38th | v4 (v2025.03.14) |
| Mar 28, 2025 | 25.12% (0.25123) | 95.72th | v4 (v2025.03.14) |
| Mar 27, 2025 | 34.77% (0.34768) | 96.45th | v4 (v2025.03.14) |
| Mar 20, 2025 | 25.12% (0.25123) | 95.75th | v4 (v2025.03.14) |
| Mar 19, 2025 | 34.77% (0.34768) | 96.50th | v4 (v2025.03.14) |
| Mar 17, 2025 | 25.12% (0.25123) | 95.72th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.12% (0.00119) | 47.78th | v3 (v2023.03.01) |
| Nov 30, 2023 | 0.12% (0.00119) | 45.90th | v3 (v2023.03.01) |
| Sep 3, 2023 | 0.10% (0.00099) | 40.24th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.09% (0.00087) | 34.99th | v3 (v2023.03.01) |
| Mar 6, 2023 | 1.51% (0.01512) | 73.61th | v2 (v2022.01.01) |
| Feb 4, 2022 | 1.51% (0.01512) | 50.79th | v2 (v2022.01.01) |
| Feb 3, 2022 | 3.63% (0.03630) | 71.73th | v5 (v2026.06.15) |
| Apr 14, 2021 | 3.63% (0.03630) | 0.00th | v1 |
References (14)
- https://access.redhat.com/security/cve/CVE-2020-8558 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1843358 Issue Tracking
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-8558
- https://github.com/advisories/GHSA-wqv3-8cm6-h6wg Advisory
- https://github.com/bottlerocket-os/bottlerocket/security/advisories/GHSA-wqv3-8cm6-h6wg
- https://github.com/kubernetes/kubernetes/issues/92315 x_refsource_CONFIRMExploitMitigationPatchThird Party Advisory
- https://github.com/tabbysable/POC-2020-8558
- https://groups.google.com/g/kubernetes-announce/c/sI4KmlH3S2I/m/TljjxOBvBQAJ mailing-listx_refsource_MLISTExploitMailing ListMitigationThird Party Advisory
- https://groups.google.com/g/kubernetes-security-announce/c/B1VegbBDMTE
- https://labs.bishopfox.com/tech-blog/bad-pods-kubernetes-pod-privilege-escalation
- https://nvd.nist.gov/vuln/detail/CVE-2020-8558
- https://security.netapp.com/advisory/ntap-20200821-0001/ x_refsource_CONFIRMThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2020-8558
- https://www.openwall.com/lists/oss-security/2020/07/08/1
Change history (0)
No recorded changes yet.