Closed
Description
In GitHub Security Advisory GHSA-33c5-9fx5-fvjm, there is a vulnerability in the following Go packages or modules:
Unit | Fixed | Vulnerable Ranges |
---|---|---|
k8s.io/apimachinery | 1.18.7 | >= 1.18.0, < 1.18.7 |
Cross references:
- Module k8s.io/apimachinery appears in issue x/vulndb: potential Go vuln in k8s.io.apimachinery #965
See doc/triage.md for instructions on how to triage this report.
modules:
- module: k8s.io/apimachinery
versions:
- introduced: 1.18.0
fixed: 1.18.7
packages:
- package: k8s.io/apimachinery
- module: k8s.io/apimachinery
versions:
- introduced: 1.17.0
fixed: 1.17.9
packages:
- package: k8s.io/apimachinery
- module: k8s.io/apimachinery
versions:
- fixed: 1.16.13
packages:
- package: k8s.io/apimachinery
summary: Privilege Escalation in Kubernetes in k8s.io/apimachinery
cves:
- CVE-2020-8559
ghsas:
- GHSA-33c5-9fx5-fvjm
references:
- web: https://nvd.nist.gov/vuln/detail/CVE-2020-8559
- report: https://github.com/kubernetes/kubernetes/issues/92914
- fix: https://github.com/kubernetes/kubernetes/pull/92941
- web: https://bugzilla.redhat.com/show_bug.cgi?id=1851422
- web: https://github.com/tdwyer/CVE-2020-8559
- web: https://groups.google.com/d/msg/kubernetes-security-announce/JAIGG5yNROs/19nHQ5wkBwAJ
- web: https://groups.google.com/g/kubernetes-security-announce/c/JAIGG5yNROs
- web: https://security.netapp.com/advisory/ntap-20200810-0004
- advisory: https://github.com/advisories/GHSA-33c5-9fx5-fvjm
source:
id: GHSA-33c5-9fx5-fvjm