MEDIUM✓ PATCH🇵🇱 Wersja polska

CVE-2020-8554

CVSS 6.3v3.1pub. 2021-01-21upd. 2026-06-01

Kubernetes API server in all versions allow an attacker who is able to create a ClusterIP service and set the spec.externalIPs field, to intercept traffic to that IP address. Additionally, an attacker who is able to patch the status (which is considered a privileged operation and should not typically be granted to users) of a LoadBalancer service can set the status.loadBalancer.ingress.ip to similar effect.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
  • Kubernetes

    APP
    Kubernetes
    all versions
  • Oracle Communications Cloud Native Core Network Slice Selection Function

    APP
    Oracle
    1.2.1
  • Oracle Communications Cloud Native Core Policy

    APP
    Oracle
    1.15.0
  • Oracle Communications Cloud Native Core Service Communication Proxy

    APP
    Oracle
    1.14.0
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
Container
CWE
References

Related vulnerabilities

CVE-2022-22963CRITICAL9.8⚠ KEVPL ✓same product

RCE w Spring Cloud Function poprzez złośliwy SpEL routing-expression

CVE-2022-22965CRITICAL9.8⚠ KEVPL ✓same product

Spring4Shell — RCE przez data binding w Spring MVC/WebFlux na JDK 9+

CVE-2022-22947CRITICAL10.0⚠ KEVPL ✓same product

RCE poprzez code injection w VMware Spring Cloud Gateway (Actuator endpoint)

CVE-2026-13019CRITICAL9.8PL ✓same product

Esri Portal for ArcGIS – brak uwierzytelnienia dla krytycznej funkcji API

CVE-2026-33519CRITICAL9.8PL ✓same product

Nieprawidłowa autoryzacja w Esri Portal for ArcGIS — obejście uprawnień