cve-2020-8558

Cve-2020-8558 | !exclusive!

This vulnerability was and assigned a CVSS v3 score of 5.9 (Medium) – later upgraded by some vendors to 7.5 due to practical exploitability in shared cluster environments. 2. Technical Root Cause 2.1 The route_localnet Setting Linux kernel parameter:

Abstract CVE-2020-8558 is a vulnerability in Kubernetes kube-proxy (versions ≤ 1.18.0) that allowed an attacker with access to a node’s pod network to bypass localhost ( 127.0.0.1 ) restrictions. Due to insufficient filtering of --nodeport-addresses and default net.ipv4.conf.all.route_localnet=1 behavior, services bound to the loopback address on a Kubernetes node became reachable from other pods or cluster nodes. This paper describes the technical root cause, exploitation vector, impact, and remediation strategies. 1. Introduction Kubernetes uses kube-proxy to manage network rules (iptables/IPVS) for Services. By design, certain node-local services (e.g., kubelet metrics, debugging endpoints) bind only to 127.0.0.1 to prevent remote access. However, CVE-2020-8558 allowed remote pods to reach those loopback-bound services by sending packets to the node’s primary IP address when route_localnet was enabled. cve-2020-8558

Negligible if fully updated, but legacy clusters remain exposed. Document version 1.0 – Security Research This vulnerability was and assigned a CVSS v3 score of 5

: Connection refused. With CVE-2020-8558 : Metrics returned. 6. Mitigation & Patching 6.1 Official Fix Kubernetes v1.18.3+ adds explicit iptables rules to drop packets arriving on non-loopback interfaces destined for 127.0.0.0/8 unless specifically allowed. Negligible if fully updated

Example rule added:

ABOUT US
Company Profile
Company Mission
PRODUCTS
Mobile SIM card
Card Reader
SIM Card Software
Card Printer
Card Ribbon
NEWS
Company News
CONTACT US
Tel:86-0755-23503790
Mobile:86-16675179838
Fax:86-0755-23503790
Contact Person:Ivy Xie
Email:sales@oyei.com
cve-2020-8558
Service
cve-2020-8558 Service one
Service oneService one
Service oneService one
客服 Service one