Oval Definition:oval:org.opensuse.security:def:20208559
Revision Date:2022-05-22Version:1
Title:CVE-2020-8559
Description:

The Kubernetes kube-apiserver in versions v1.6-v1.15, and versions prior to v1.16.13, v1.17.9 and v1.18.6 are vulnerable to an unvalidated redirect on proxied upgrade requests that could allow an attacker to escalate privileges from a node compromise to a full cluster compromise.
Family:unixClass:vulnerability
Status:Reference(s):Mitre CVE-2020-8559
SUSE CVE-2020-8559
Platform(s):SUSE CaaS Platform 4.0
SUSE Linux Enterprise Server for SAP Applications 15 SP1
SUSE Manager Proxy 4.0
SUSE Manager Retail Branch Server 4.0
SUSE Manager Server 4.0
Product(s):
Definition Synopsis
  • Release Information
  • SUSE CaaS Platform 4.0 is installed
  • AND
  • kubernetes-client is affected
  • OR kubernetes-common is affected
  • OR kubernetes-kubeadm is affected
  • OR kubernetes-kubelet is affected
  • OR Package Information
  • SUSE Linux Enterprise Server for SAP Applications 15 SP1 is installed
  • AND
  • kubernetes-client is affected
  • OR kubernetes-common is affected
  • Definition Synopsis
  • Release Information
  • SUSE Manager Proxy 4.0 is installed
  • OR SUSE Manager Retail Branch Server 4.0 is installed
  • OR SUSE Manager Server 4.0 is installed
  • AND kubernetes is affected
  • OR Package Information
  • SUSE Linux Enterprise Server for SAP Applications 15 SP1 is installed
  • AND
  • kubernetes-client is affected
  • OR kubernetes-common is affected
  • BACK