Database/Container, Kubernetes & orchestration
Kubernetes (kubelet/kube-proxy): Node's 127.0.0.1-bound services reachable from adjacent hosts and pods
CVE-2020-8558Container, Kubernetes & orchestrationcurated
Impact
Node's 127.0.0.1-bound services reachable from adjacent hosts and pods; commonly reaches an unauthenticated kubelet or etcd
Who can reach it
Any pod on the node, or an adjacent host on the node network
What to do
Rolling kubelet/kube-proxy upgrade with node drain
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.