CVE-2020-8554
Kubernetes API server in all versions allow an attacker who is able to create a ClusterIP service and set the spec.externalIPs field, to intercept traffic to that IP address. Additionally, an attacker who is able to patch the status (which is considered a privileged operation and should not typically be granted to users) of a LoadBalancer service can set the status.loadBalancer.ingress.ip to similar effect.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 6.3
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
- EPSS probability
- 30.41%
- CWE
- CWE-283
- Published
- 2021-01-21
- Last modified
- 2026-06-01
Affected products
- Kubernetes Kubernetes
- Kubernetes Kubernetes
Weakness type
Related vulnerabilities
- CVE-2026-26016 — Pterodactyl Panel Allows Cross-Node Server Configuration Disclosure via Remote API Missing Authorization
- CVE-2026-29788 — TSPortal: Anyone can forge self-deletion requests of any user
- CVE-2025-43882 — Dell ThinOS 10, versions prior to 2508_10.0127, contains an Unverified Ownership vulnerability. A local low-privileged a
- CVE-2026-4269 — Improper S3 ownership verification in Bedrock AgentCore Starter Toolkit
- CVE-2025-47940 — TYPO3 CMS Vulnerable to Privilege Escalation to System Maintainer
- CVE-2025-1007 — Improper Authorization in /user/namespace/{namespace}/details
- CVE-2024-27903 — OpenVPN plug-ins on Windows with OpenVPN 2.6.9 and earlier could be loaded from any directory, which allows an attacker
- CVE-2022-29220 — No verification of commits origin in github-action-merge-dependabot