CVE-2020-8552
published 2020-03-27CVE-2020-8552: The Kubernetes API server component in versions prior to 1.15.9, 1.16.0-1.16.6, and 1.17.0-1.17.2 has been found to be vulnerable to a denial of service attack…
PriorityP422medium4.3CVSS 3.1
AVNACLPRLUINSUCNINAL
EPSS
2.43%
82.5th percentile
The Kubernetes API server component in versions prior to 1.15.9, 1.16.0-1.16.6, and 1.17.0-1.17.2 has been found to be vulnerable to a denial of service attack via successful API requests.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | kubernetes | < kubernetes 1.17.4-1 (bookworm) | kubernetes 1.17.4-1 (bookworm) |
| fedoraproject | fedora | — | — |
| k8s.io | apiserver | >= 0 < 0.15.10 | 0.15.10 |
| k8s.io | apiserver | >= 0.16.0 < 0.16.7 | 0.16.7 |
| k8s.io | apiserver | >= 0.17.0 < 0.17.3 | 0.17.3 |
| kubernetes | kubernetes | <= 1.15.9 | — |
| kubernetes | kubernetes | >= 0 < 1.17.4-1 | 1.17.4-1 |
| kubernetes | kubernetes | >= 0 < 1.17.4-1 | 1.17.4-1 |
| kubernetes | kubernetes | >= 0 < 1.17.4-1 | 1.17.4-1 |
| kubernetes | kubernetes | >= 0 < 1.17.4-1 | 1.17.4-1 |
| kubernetes | kubernetes | 1.16.0 – 1.16.6 | — |
| kubernetes | kubernetes | 1.17.0 – 1.17.2 | — |
| kubernetes | kubernetes | >= unspecified < v1.17.3 | v1.17.3 |
| kubernetes | kubernetes | >= unspecified < v1.16.7 | v1.16.7 |
| kubernetes | kubernetes | >= unspecified < v1.15.10 | v1.15.10 |
CVSS provenance
nvdv3.14.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:N/I:N/A:P
osv4.3MEDIUM
vendor_debian5.3MEDIUM
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Kubernetes API Server DoS Via API Requests
ghsa·2022-02-15
CVE-2020-8552 [MEDIUM] CWE-400 Kubernetes API Server DoS Via API Requests
Kubernetes API Server DoS Via API Requests
The Kubernetes API server component in Kubernetes versions prior to 1.15.9, 1.16.0-1.16.6, and 1.17.0-1.17.2 has been found to be vulnerable to a denial of service attack via successful API requests.
OSV
Kubernetes API Server DoS Via API Requests
osv·2022-02-15
CVE-2020-8552 [MEDIUM] Kubernetes API Server DoS Via API Requests
Kubernetes API Server DoS Via API Requests
The Kubernetes API server component in Kubernetes versions prior to 1.15.9, 1.16.0-1.16.6, and 1.17.0-1.17.2 has been found to be vulnerable to a denial of service attack via successful API requests.
OSV
CVE-2020-8552: The Kubernetes API server component in versions prior to 1
osv·2020-03-27·CVSS 4.3
CVE-2020-8552 [MEDIUM] CVE-2020-8552: The Kubernetes API server component in versions prior to 1
The Kubernetes API server component in versions prior to 1.15.9, 1.16.0-1.16.6, and 1.17.0-1.17.2 has been found to be vulnerable to a denial of service attack via successful API requests.
Red Hat
kubernetes: Use of unbounded 'client' label in apiserver_request_total allows for memory exhaustion
vendor_redhat·2020-03-23·CVSS 5.3
CVE-2020-8552 [MEDIUM] CWE-400 kubernetes: Use of unbounded 'client' label in apiserver_request_total allows for memory exhaustion
kubernetes: Use of unbounded 'client' label in apiserver_request_total allows for memory exhaustion
The Kubernetes API server component in versions prior to 1.15.9, 1.16.0-1.16.6, and 1.17.0-1.17.2 has been found to be vulnerable to a denial of service attack via successful API requests.
A denial of service vulnerability was found in the Kubernetes API server. This flaw allows a remote attacker to send repeated, crafted HTTP requests to exhaust available memory and cause a crash.
Mitigation: Prevent unauthenticated or unauthorized access to all APIs
Package: openshift4/ose-hypershift (Red Hat OpenShift Container Platform 4) - Will not fix
Package: openshift4/ose-service-catalog (Red Hat OpenShift Container Platform 4) - Will not fix
Package: heketi (Red Hat Storage 3) - Not affected
Debian
CVE-2020-8552: kubernetes - The Kubernetes API server component in versions prior to 1.15.9, 1.16.0-1.16.6, ...
vendor_debian·2020·CVSS 5.3
CVE-2020-8552 [MEDIUM] CVE-2020-8552: kubernetes - The Kubernetes API server component in versions prior to 1.15.9, 1.16.0-1.16.6, ...
The Kubernetes API server component in versions prior to 1.15.9, 1.16.0-1.16.6, and 1.17.0-1.17.2 has been found to be vulnerable to a denial of service attack via successful API requests.
Scope: local
bookworm: resolved (fixed in 1.17.4-1)
bullseye: resolved (fixed in 1.17.4-1)
forky: resolved (fixed in 1.17.4-1)
sid: resolved (fixed in 1.17.4-1)
trixie: resolved (fixed in 1.17.4-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2020-8552 kubernetes: Use of unbounded 'client' label in apiserver_request_total allows for memory exhaustion [fedora-all]
bugzilla·2020-03-23·CVSS 5.3
CVE-2020-8552 [MEDIUM] CVE-2020-8552 kubernetes: Use of unbounded 'client' label in apiserver_request_total allows for memory exhaustion [fedora-all]
CVE-2020-8552 kubernetes: Use of unbounded 'client' label in apiserver_request_total allows for memory exhaustion [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOT
Bugzilla
CVE-2020-8552 origin: kubernetes: Use of unbounded 'client' label in apiserver_request_total allows for memory exhaustion [fedora-all]
bugzilla·2020-03-23·CVSS 5.3
CVE-2020-8552 [MEDIUM] CVE-2020-8552 origin: kubernetes: Use of unbounded 'client' label in apiserver_request_total allows for memory exhaustion [fedora-all]
CVE-2020-8552 origin: kubernetes: Use of unbounded 'client' label in apiserver_request_total allows for memory exhaustion [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit messa
Bugzilla
CVE-2020-8552 kubernetes: Use of unbounded 'client' label in apiserver_request_total allows for memory exhaustion
bugzilla·2020-02-04·CVSS 5.3
CVE-2020-8552 [MEDIUM] CVE-2020-8552 kubernetes: Use of unbounded 'client' label in apiserver_request_total allows for memory exhaustion
CVE-2020-8552 kubernetes: Use of unbounded 'client' label in apiserver_request_total allows for memory exhaustion
A flaw was found in the Kubernetes API server that allows for memory exhaustion and subsequent denial of service. A label in a Kubernetes apiserver metric that reflects the client's user agent is included for debugging purposes, but every value added adds a sustained memory overhead as the metric is now tracked. This is particularly dangerous on commonly unauthenticated APIs (selfsubjectaccessreview for example) and can be performed by any authenticated user.
Upstream Fixes:
1.18: https://github.com/kubernetes/kubernetes/pull/87669
1.17: https://github.com/kubernetes/kubernetes/pull/87673
1.16: https://github.com/kubernetes/kubernetes/pull/87681
1.15: https://github.com/kub
https://github.com/kubernetes/kubernetes/issues/89378https://groups.google.com/forum/#%21topic/kubernetes-security-announce/2UOlsba2g0shttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3SOCLOPTSYABTE4CLTSPDIFE6ZZZR4LX/https://security.netapp.com/advisory/ntap-20200413-0003/https://github.com/kubernetes/kubernetes/issues/89378https://groups.google.com/forum/#%21topic/kubernetes-security-announce/2UOlsba2g0shttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3SOCLOPTSYABTE4CLTSPDIFE6ZZZR4LX/https://security.netapp.com/advisory/ntap-20200413-0003/
2020-03-27
Published