Back to bug 1954914

Who When What Removed Added
Sam Fowler 2021-04-29 04:25:56 UTC CC security-response-team
Sam Fowler 2021-04-29 04:26:26 UTC Blocks 1954915
Sam Fowler 2021-04-29 08:09:23 UTC Depends On 1954981, 1954980
Florencio Cano 2021-05-03 07:45:14 UTC Depends On 1956192, 1956194, 1956193
Sam Fowler 2021-05-04 22:36:42 UTC Group security, qe_staff
CC admiller, jcajka
Deadline 2021-05-04
Summary EMBARGOED CVE-2020-8562 kubernetes: Bypass of Kubernetes API Server proxy TOCTOU CVE-2020-8562 kubernetes: Bypass of Kubernetes API Server proxy TOCTOU
Sam Fowler 2021-05-04 23:47:24 UTC Doc Text A security issue was discovered in Kubernetes where an authorized user may be able to access private networks on the Kubernetes control plane components. Kubernetes clusters are only affected if an untrusted user can create or modify Node objects and proxy to them, or an untrusted user can create or modify StorageClass objects and access KubeControllerManager logs.
Sam Fowler 2021-05-04 23:48:04 UTC Depends On 1957061
Stefan Schimanski 2021-05-06 08:45:15 UTC CC anachand
Red Hat Bugzilla 2022-01-08 05:28:11 UTC CC jokerman
Red Hat Bugzilla 2022-11-13 17:07:52 UTC CC anachand
Red Hat Bugzilla 2023-03-29 23:17:19 UTC CC lhinds
Red Hat Bugzilla 2023-04-29 08:27:57 UTC CC sttts
Red Hat Bugzilla 2023-07-07 08:29:01 UTC Assignee security-response-team nobody
CC security-response-team

Back to bug 1954914