Vulnerability record · CVE-2020-8559 · published 22 July 2020
CVE-2020-8559: Kubernetes open redirect vulnerability
Kubernetes · Kubernetes
The Kubernetes kube-apiserver in versions v1.6-v1.15, and versions prior to v1.16.13, v1.17.9 and v1.18.6 are vulnerable to an unvalidated redirect on proxied upgrade requests that could allow an attacker to escalate privileges from a node compromise to a full cluster compromise.
Description
The Kubernetes kube-apiserver in versions v1.6-v1.15, and versions prior to v1.16.13, v1.17.9 and v1.18.6 are vulnerable to an unvalidated redirect on proxied upgrade requests that could allow an attacker to escalate privileges from a node compromise to a full cluster compromise.
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://github.com/kubernetes/kubernetes/issues/92914 | ExploitIssue TrackingPatchThird Party Advisory |
| https://groups.google.com/d/msg/kubernetes-security-announce/JAIGG5yNROs/19nHQ5wkBwAJ | ExploitThird Party Advisory |
| https://security.netapp.com/advisory/ntap-20200810-0004/ | Third Party Advisory |
| https://github.com/kubernetes/kubernetes/issues/92914 | ExploitIssue TrackingPatchThird Party Advisory |
| https://groups.google.com/d/msg/kubernetes-security-announce/JAIGG5yNROs/19nHQ5wkBwAJ | ExploitThird Party Advisory |
| https://security.netapp.com/advisory/ntap-20200810-0004/ | Third Party Advisory |
Track CVE-2020-8559 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2020-8559), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.