HomeSecurityAll versions of Kubernetes are affected by a vulnerability

All versions of Kubernetes are affected by a vulnerability

The Kubernetes Product Security Committee has provided advice on how to temporarily prevent attackers from exploiting a vulnerability that would allow them to monitor traffic from other pods in multi-tenant Kubernetes clusters in man-in-the-middle (MiTM) attacks.

Kubernetes

Kubernetes (also known as K8s), originally developed by Google and now maintained by the Cloud Native Computing Foundation, is an open source designed to help automate the deployment, scaling, and management of workloads, services, and applications that facilitates both configuration and automation.

The affected services are not widely deployed

The medium severity security issue is listed as CVE-2020-8554 and was reported by Etienne Champetier of Anevia.

It can be exploited remotely by attackers with basic tenant privileges (such as creating or editing services and pods) without user interaction as part of low- sophistication.

CVE-2020-8554 is a design flaw that affects all Kubernetes versions, with multi-tenant clusters that allow tenants to create and update services and pods being the most vulnerable to attacks.

Fortunately, the vulnerability should affect a small number of Kubernetes deployments, since external IP services are not used extensively in multi-tenant clusters.

How to block CVE-2020-8554 exploits

Because the Kubernetes development team has not yet provided a security update to address this issue, administrators to mitigate CVE-2020-8554 by restricting access to vulnerable features.

You can use an import webhook container to restrict external IP usage – source code and deployment instructions are available here.

External IP addresses can also be restricted with the help of the Open Policy Agent Gatekeeper for Kubernetes using restrictions and templates which are available here.

To detect attacks that attempt to exploit this vulnerability, you must manually check external IP usage in multi-tenant clusters using the vulnerable capabilities .

Information source: bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS