Access Restriction Bypass Affecting k8s.io/kubernetes/pkg package, versions *


Severity

Recommended
0.0
low
0
10

CVSS assessment made by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.08% (35th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-GOLANG-K8SIOKUBERNETESPKG-2389037
  • published1 Feb 2022
  • disclosed1 Feb 2022
  • creditJavier Provecho

Introduced: 1 Feb 2022

CVE-2020-8562  (opens in a new tab)
CWE-367  (opens in a new tab)

How to fix?

There is no fixed version for k8s.io/kubernetes/pkg.

Overview

k8s.io/kubernetes/pkg is a Kubernetes, also known as K8s, is an open source system for managing containerized applications across multiple hosts. It provides basic mechanisms for deployment, maintenance, and scaling of applications.

Kubernetes builds upon a decade and a half of experience at Google running production workloads at scale using a system called Borg, combined with best-of-breed ideas and practices from the community.

Affected versions of this package are vulnerable to Access Restriction Bypass when performing a second DNS resolution without validation for the actual connection. If a non-standard DNS server returns different non-cached responses, a user may be able to bypass the proxy IP restriction and access private networks on the control plane.

CVSS Scores

version 3.1