logo

Unpatchable Vulnerabilities of Kubernetes: CVE-2020-8561

ID: 6d7cdf16-686c-54ed-8a4f-3dfc579df719

STIX ID: report--6d7cdf16-686c-54ed-8a4f-3dfc579df719

Feed Name: Datadog Security Labs

Threat Score
55/100

Date Published: 2026-03-27

Date Updated: 2026-04-27

...
...

This report examines CVE-2020-8561, which combines an SSRF vector in the Kubernetes API server (using validatingwebhookconfigurations) with the API server's profiling endpoint to increase log verbosity and capture SSRF responses; the analysis describes the attack flow, proof-of-concept steps (including PUT to /debug/flags/v and creation of a malicious ValidatingWebhookConfiguration), the conditions that increase impact (especially managed control planes and network segmentation), and recommended mitigations such as disabling --profiling and segregating control-plane network access.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.