SB2022110606 - Time-of-check time-of-use (TOCTOU) race condition in Kubernetes
Published: November 6, 2022 Updated: July 23, 2024
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Time-of-check Time-of-use (TOCTOU) Race Condition (CVE-ID: CVE-2020-8562)
The vulnerability allows a remote privileged user to gain access to potentially sensitive information.
The vulnerability exists due to a time-of-check time-of-use (TOCTOU) race condition flaw in the API Server proxy. A remote privileged user can send a specially-crafted request and exploit this vulnerability to gain access to private networks on the Kubernetes control plane components.
Remediation
Install update from vendor's website.