Skip to content

Kubernetes CVE-2020-8557

Moderate
etungsten published GHSA-fpgg-9xgf-f2wm Aug 17, 2020

Package

kubernetes-1.15, kubernetes-1.16, kubernetes-1.17 (bottlerocket)

Affected versions

< 0.5.0

Patched versions

0.5.0

Description

A flaw was found in Kubernetes, where the amount of disk space the /etc/hosts file can use is unconstrained. This flaw can allow attacker-controlled pods to cause a denial of service if they have permission to write to the node's /etc/hosts file.

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-8557
https://www.openwall.com/lists/oss-security/2020/07/15/4

Severity

Moderate

CVE ID

CVE-2020-8557

Weaknesses

No CWEs