Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2018-1002100

Опубликовано: 02 июн. 2018
Источник: debian
EPSS Низкий

Описание

In Kubernetes versions 1.5.x, 1.6.x, 1.7.x, 1.8.x, and prior to version 1.9.6, the kubectl cp command insecurely handles tar data returned from the container, and can be caused to overwrite arbitrary local files.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
kubernetesfixed1.17.4-1package

Примечания

  • https://github.com/kubernetes/kubernetes/issues/61297

  • https://github.com/kubernetes/kubernetes/commit/f180c969ccd47b9d00dbaf5cbd5b37eb8b49ae08 (1.9.x)

EPSS

Процентиль: 68%
0.00579
Низкий

Связанные уязвимости

CVSS3: 4.2
ubuntu
около 7 лет назад

In Kubernetes versions 1.5.x, 1.6.x, 1.7.x, 1.8.x, and prior to version 1.9.6, the kubectl cp command insecurely handles tar data returned from the container, and can be caused to overwrite arbitrary local files.

CVSS3: 6.1
redhat
больше 7 лет назад

In Kubernetes versions 1.5.x, 1.6.x, 1.7.x, 1.8.x, and prior to version 1.9.6, the kubectl cp command insecurely handles tar data returned from the container, and can be caused to overwrite arbitrary local files.

CVSS3: 4.2
nvd
около 7 лет назад

In Kubernetes versions 1.5.x, 1.6.x, 1.7.x, 1.8.x, and prior to version 1.9.6, the kubectl cp command insecurely handles tar data returned from the container, and can be caused to overwrite arbitrary local files.

CVSS3: 5.5
github
около 3 лет назад

Kubernetes arbitrary file overwrite

EPSS

Процентиль: 68%
0.00579
Низкий