Vulnerability Description
The Kubernetes ingress-nginx component prior to version 0.28.0 allows a user with the ability to create namespaces and to read and create ingress objects to overwrite the password file of another ingress which uses nginx.ingress.kubernetes.io/auth-type: basic and which has a hyphenated namespace or secret name.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Kubernetes | Ingress-Nginx | < 0.28.0 |
Related Weaknesses (CWE)
References
- https://github.com/kubernetes/ingress-nginx/issues/5126Third Party Advisory
- https://github.com/kubernetes/ingress-nginx/issues/5126Third Party Advisory
FAQ
What is CVE-2020-8553?
CVE-2020-8553 is a vulnerability with a CVSS score of 5.9 (MEDIUM). The Kubernetes ingress-nginx component prior to version 0.28.0 allows a user with the ability to create namespaces and to read and create ingress objects to overwrite the password file of another ingr...
How severe is CVE-2020-8553?
CVE-2020-8553 has been rated MEDIUM with a CVSS base score of 5.9/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-8553?
Check the references section above for vendor advisories and patch information. Affected products include: Kubernetes Ingress-Nginx.