Unpatchable Vulnerabilities of Kubernetes: CVE-2020-8561
ID: 6d7cdf16-686c-54ed-8a4f-3dfc579df719
STIX ID: report--6d7cdf16-686c-54ed-8a4f-3dfc579df719
Feed Name: Datadog Security Labs
This report examines CVE-2020-8561, which combines an SSRF vector in the Kubernetes API server (using validatingwebhookconfigurations) with the API server's profiling endpoint to increase log verbosity and capture SSRF responses; the analysis describes the attack flow, proof-of-concept steps (including PUT to /debug/flags/v and creation of a malicious ValidatingWebhookConfiguration), the conditions that increase impact (especially managed control planes and network segmentation), and recommended mitigations such as disabling --profiling and segregating control-plane network access.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
