Kubernetes man in the middle using LoadBalancer or ExternalIPs
Summary
| CVE | CVE-2020-8554 |
|---|---|
| State | PUBLISHED |
| Assigner | kubernetes |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-01-21 17:15:13 UTC |
| Updated | 2026-06-01 23:16:13 UTC |
| Description | Kubernetes API server in all versions allow an attacker who is able to create a ClusterIP service and set the spec.externalIPs field, to intercept traffic to that IP address. Additionally, an attacker who is able to patch the status (which is considered a privileged operation and should not typically be granted to users) of a LoadBalancer service can set the status.loadBalancer.ingress.ip to similar effect. |
Risk And Classification
Primary CVSS: v3.1 5 MEDIUM from [email protected]
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L
EPSS: 0.092740000 probability, percentile 0.948200000 (date 2026-07-21)
Problem Types: CWE-283 | NVD-CWE-noinfo | CWE-283 CWE-283 Unverified Ownership
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | [email protected] | Primary | 5 | MEDIUM | CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L |
| 3.1 | [email protected] | Secondary | 6.3 | MEDIUM | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L |
| 3.1 | CNA | DECLARED | 6.3 | MEDIUM | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L |
| 2.0 | [email protected] | Primary | 6 | AV:N/AC:M/Au:S/C:P/I:P/A:P |
CVSS v3.1 Breakdown
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L
CVSS v2.0 Breakdown
AV:N/AC:M/Au:S/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Kubernetes | Kubernetes | All | All | All | All |
| Application | Oracle | Communications Cloud Native Core Network Slice Selection Function | 1.2.1 | All | All | All |
| Application | Oracle | Communications Cloud Native Core Policy | 1.15.0 | All | All | All |
| Application | Oracle | Communications Cloud Native Core Service Communication Proxy | 1.14.0 | All | All | All |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Kubernetes | Kubernetes | affected * semver | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| [Security Advisory] CVE-2020-8554: Man in the middle using LoadBalancer or ExternalIPs | af854a3a-2127-422b-91ae-364da2661108 | groups.google.com | Mailing List, Third Party Advisory |
| Oracle Critical Patch Update Advisory - April 2022 | af854a3a-2127-422b-91ae-364da2661108 | www.oracle.com | Patch, Third Party Advisory |
| Pony Mail! | af854a3a-2127-422b-91ae-364da2661108 | lists.apache.org | |
| Oracle Critical Patch Update Advisory - July 2021 | af854a3a-2127-422b-91ae-364da2661108 | www.oracle.com | Patch, Third Party Advisory |
| Oracle Critical Patch Update Advisory - January 2022 | af854a3a-2127-422b-91ae-364da2661108 | www.oracle.com | Patch, Third Party Advisory |
| RESERVED · Issue #97076 · kubernetes/kubernetes · GitHub | af854a3a-2127-422b-91ae-364da2661108 | github.com | Exploit, Third Party Advisory |
| Pony Mail! | af854a3a-2127-422b-91ae-364da2661108 | lists.apache.org | |
| kubernetes.io/blog/2026/05/26/reconciling-unfixed-kubernetes-cves | [email protected] | kubernetes.io | |
| Pony Mail! | af854a3a-2127-422b-91ae-364da2661108 | lists.apache.org | |
| Pony Mail! | af854a3a-2127-422b-91ae-364da2661108 | lists.apache.org | |
| Pony Mail! | MITRE | lists.apache.org | |
| Pony Mail! | MITRE | lists.apache.org | |
| Pony Mail! | MITRE | lists.apache.org | |
| Pony Mail! | MITRE | lists.apache.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
CNA: Etienne Champetier (@champtar) of Anevia (en)
Additional Advisory Data
Workarounds
CNA: To restrict the use of external IPs we are providing an admission webhook container: k8s.gcr.io/multitenancy/externalip-webhook:v1.0.0. The source code and deployment instructions are published at https://github.com/kubernetes-sigs/externalip-webhook. Alternatively, external IPs can be restricted using OPA Gatekeeper. A sample ConstraintTemplate and Constraint can be found here: https://github.com/open-policy-agent/gatekeeper-library/tree/master/library/general/externalip.
Legacy QID Mappings
- 900263 CBL-Mariner Linux Security Update for kubernetes-1.18.17 1.18.17
- 900264 CBL-Mariner Linux Security Update for kubernetes 1.18.17
- 900265 CBL-Mariner Linux Security Update for kubernetes-1.18.14 1.18.14
- 900266 CBL-Mariner Linux Security Update for kubernetes-1.19.7 1.19.7
- 900267 CBL-Mariner Linux Security Update for kubernetes-1.19.9 1.19.9
- 900268 CBL-Mariner Linux Security Update for kubernetes-1.20.2 1.20.2
- 900269 CBL-Mariner Linux Security Update for kubernetes-1.20.5 1.20.5
- 900270 CBL-Mariner Linux Security Update for python-kubernetes 11.0.0
- 903524 Common Base Linux Mariner (CBL-Mariner) Security Update for kubernetes (6284)
- 905971 Common Base Linux Mariner (CBL-Mariner) Security Update for kubernetes (6284-1)
- 907546 Common Base Linux Mariner (CBL-Mariner) Security Update for kubernetes (31731-1)