Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2018-1002100

Опубликовано: 02 июн. 2018
Источник: debian

Описание

In Kubernetes versions 1.5.x, 1.6.x, 1.7.x, 1.8.x, and prior to version 1.9.6, the kubectl cp command insecurely handles tar data returned from the container, and can be caused to overwrite arbitrary local files.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
kubernetesfixed1.17.4-1package

Примечания

  • https://github.com/kubernetes/kubernetes/issues/61297

  • https://github.com/kubernetes/kubernetes/commit/f180c969ccd47b9d00dbaf5cbd5b37eb8b49ae08 (1.9.x)

Связанные уязвимости

CVSS3: 4.2
ubuntu
около 8 лет назад

In Kubernetes versions 1.5.x, 1.6.x, 1.7.x, 1.8.x, and prior to version 1.9.6, the kubectl cp command insecurely handles tar data returned from the container, and can be caused to overwrite arbitrary local files.

CVSS3: 6.1
redhat
больше 8 лет назад

In Kubernetes versions 1.5.x, 1.6.x, 1.7.x, 1.8.x, and prior to version 1.9.6, the kubectl cp command insecurely handles tar data returned from the container, and can be caused to overwrite arbitrary local files.

CVSS3: 4.2
nvd
около 8 лет назад

In Kubernetes versions 1.5.x, 1.6.x, 1.7.x, 1.8.x, and prior to version 1.9.6, the kubectl cp command insecurely handles tar data returned from the container, and can be caused to overwrite arbitrary local files.

CVSS3: 5.5
github
около 4 лет назад

Kubernetes arbitrary file overwrite