CVE-2020-8552Medium· 5.3▾ SunlitKubernetes API Server DoS Via API Requests
▾ Sunlit zone — Low / medium · no exploitation signal
impact 29.2 · likelihood 0.5 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 12.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
2.4%
The Kubernetes API server component in Kubernetes versions prior to 1.15.9, 1.16.0-1.16.6, and 1.17.0-1.17.2 has been found to be vulnerable to a denial of service attack via successful API requests.
k8s.io/apiserver < 0.15.10k8s.io/apiserver >= 0.16.0, < 0.16.7k8s.io/apiserver >= 0.17.0, < 0.17.3Upgrade to a patched release:
k8s.io/apiserver 0.15.10k8s.io/apiserver 0.16.7k8s.io/apiserver 0.17.3