QSearchQSearch

CVE-2020-8554

6.3 MEDIUM

Kubernetes API server in all versions allow an attacker who is able to create a ClusterIP service and set the spec.externalIPs field, to ...

Published: 2021-01-21 · Last updated: 2026-06-01

Severity and scoring

CVSS
6.3 MEDIUM
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
CWE
CWE-283

Affected products

VendorProduct
kubernetescommunications_cloud_native_core_network_slice_selection_function, communications_cloud_native_core_policy, communications_cloud_native_core_service_communication_proxy
oraclecommunications_cloud_native_core_network_slice_selection_function, communications_cloud_native_core_policy, communications_cloud_native_core_service_communication_proxy

Description

Kubernetes API server in all versions allow an attacker who is able to create a ClusterIP service and set the spec.externalIPs field, to intercept traffic to that IP address. Additionally, an attacker who is able to patch the status (which is considered a privileged operation and should not typically be granted to users) of a LoadBalancer service can set the status.loadBalancer.ingress.ip to similar effect.

Source: NVD

References

Related CVEs

Same vendor

  • CVE-2026-46843 Vulnerability in Oracle REST Data Services (component: Core) (5.3 MEDIUM)
  • CVE-2026-46842 Vulnerability in Oracle REST Data Services (component: Core) (5.3 MEDIUM)
  • CVE-2026-46841 Vulnerability in Oracle REST Data Services (component: General) (5.3 MEDIUM)
  • CVE-2026-46840 Vulnerability in Oracle REST Data Services (component: Backend-as-a-Service) (10.0 CRITICAL)
  • CVE-2026-46839 Vulnerability in Oracle REST Data Services (component: Core) (9.9 CRITICAL)

Same CWE

  • CVE-2026-44707 Chatwoot is a customer engagement suite (6.8 MEDIUM)
  • CVE-2026-44562 Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline (6.5 MEDIUM)