Skip to content

x/vulndb: potential Go vuln in k8s.io/apimachinery: GHSA-33c5-9fx5-fvjm #2748

Closed
@GoVulnBot

Description

@GoVulnBot

In GitHub Security Advisory GHSA-33c5-9fx5-fvjm, there is a vulnerability in the following Go packages or modules:

Unit Fixed Vulnerable Ranges
k8s.io/apimachinery 1.18.7 >= 1.18.0, < 1.18.7

Cross references:

See doc/triage.md for instructions on how to triage this report.

modules:
    - module: k8s.io/apimachinery
      versions:
        - introduced: 1.18.0
          fixed: 1.18.7
      packages:
        - package: k8s.io/apimachinery
    - module: k8s.io/apimachinery
      versions:
        - introduced: 1.17.0
          fixed: 1.17.9
      packages:
        - package: k8s.io/apimachinery
    - module: k8s.io/apimachinery
      versions:
        - fixed: 1.16.13
      packages:
        - package: k8s.io/apimachinery
summary: Privilege Escalation in Kubernetes in k8s.io/apimachinery
cves:
    - CVE-2020-8559
ghsas:
    - GHSA-33c5-9fx5-fvjm
references:
    - web: https://nvd.nist.gov/vuln/detail/CVE-2020-8559
    - report: https://github.com/kubernetes/kubernetes/issues/92914
    - fix: https://github.com/kubernetes/kubernetes/pull/92941
    - web: https://bugzilla.redhat.com/show_bug.cgi?id=1851422
    - web: https://github.com/tdwyer/CVE-2020-8559
    - web: https://groups.google.com/d/msg/kubernetes-security-announce/JAIGG5yNROs/19nHQ5wkBwAJ
    - web: https://groups.google.com/g/kubernetes-security-announce/c/JAIGG5yNROs
    - web: https://security.netapp.com/advisory/ntap-20200810-0004
    - advisory: https://github.com/advisories/GHSA-33c5-9fx5-fvjm
source:
    id: GHSA-33c5-9fx5-fvjm

Metadata

Metadata

Assignees

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions