MEDIUM5.3
GHSA-82hx-w2r5-c2wq
Kubernetes API Server DoS Via API Requests
Quick fix
GHSA-82hx-w2r5-c2wq — k8s.io/apiserver: upgrade to the fixed version with the command below.
go get k8s.io/apiserver@v0.15.10Details
The Kubernetes API server component in Kubernetes versions prior to 1.15.9, 1.16.0-1.16.6, and 1.17.0-1.17.2 has been found to be vulnerable to a denial of service attack via successful API requests.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2020-8552[ADVISORY]
- https://github.com/kubernetes/kubernetes/issues/89378[WEB]
- https://github.com/kubernetes/kubernetes/pull/87669[WEB]
- https://github.com/kubernetes/kubernetes/commit/5978856c4c7f10737a11c9540fe60b8475beecbb[WEB]
- https://groups.google.com/forum/#!topic/kubernetes-security-announce/2UOlsba2g0s[WEB]
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/3SOCLOPTSYABTE4CLTSPDIFE6ZZZR4LX[WEB]
- https://security.netapp.com/advisory/ntap-20200413-0003[WEB]