Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2017-1002100

Опубликовано: 14 сент. 2017
Источник: nvd
CVSS3: 6.5
CVSS2: 4
EPSS Низкий

Описание

Default access permissions for Persistent Volumes (PVs) created by the Kubernetes Azure cloud provider in versions 1.6.0 to 1.6.5 are set to "container" which exposes a URI that can be accessed without authentication on the public internet. Access to the URI string requires privileged access to the Kubernetes cluster or authenticated access to the Azure portal.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:kubernetes:kubernetes:1.6.0:*:*:*:*:*:*:*
cpe:2.3:a:kubernetes:kubernetes:1.6.0:alpha.0:*:*:*:*:*:*
cpe:2.3:a:kubernetes:kubernetes:1.6.0:alpha.1:*:*:*:*:*:*
cpe:2.3:a:kubernetes:kubernetes:1.6.0:alpha.2:*:*:*:*:*:*
cpe:2.3:a:kubernetes:kubernetes:1.6.0:alpha.3:*:*:*:*:*:*
cpe:2.3:a:kubernetes:kubernetes:1.6.0:beta.0:*:*:*:*:*:*
cpe:2.3:a:kubernetes:kubernetes:1.6.0:beta.1:*:*:*:*:*:*
cpe:2.3:a:kubernetes:kubernetes:1.6.0:beta.2:*:*:*:*:*:*
cpe:2.3:a:kubernetes:kubernetes:1.6.0:beta.3:*:*:*:*:*:*
cpe:2.3:a:kubernetes:kubernetes:1.6.0:beta.4:*:*:*:*:*:*
cpe:2.3:a:kubernetes:kubernetes:1.6.0:rc.1:*:*:*:*:*:*
cpe:2.3:a:kubernetes:kubernetes:1.6.1:*:*:*:*:*:*:*
cpe:2.3:a:kubernetes:kubernetes:1.6.1:beta.0:*:*:*:*:*:*
cpe:2.3:a:kubernetes:kubernetes:1.6.2:*:*:*:*:*:*:*
cpe:2.3:a:kubernetes:kubernetes:1.6.2:beta.0:*:*:*:*:*:*
cpe:2.3:a:kubernetes:kubernetes:1.6.3:*:*:*:*:*:*:*
cpe:2.3:a:kubernetes:kubernetes:1.6.3:beta.0:*:*:*:*:*:*
cpe:2.3:a:kubernetes:kubernetes:1.6.3:beta.1:*:*:*:*:*:*
cpe:2.3:a:kubernetes:kubernetes:1.6.4:*:*:*:*:*:*:*
cpe:2.3:a:kubernetes:kubernetes:1.6.4:beta.0:*:*:*:*:*:*
cpe:2.3:a:kubernetes:kubernetes:1.6.4:beta.1:*:*:*:*:*:*
cpe:2.3:a:kubernetes:kubernetes:1.6.5:*:*:*:*:*:*:*
cpe:2.3:a:kubernetes:kubernetes:1.6.5:beta.0:*:*:*:*:*:*

EPSS

Процентиль: 58%
0.00368
Низкий

6.5 Medium

CVSS3

4 Medium

CVSS2

Дефекты

CWE-200

Связанные уязвимости

CVSS3: 6.5
redhat
около 8 лет назад

Default access permissions for Persistent Volumes (PVs) created by the Kubernetes Azure cloud provider in versions 1.6.0 to 1.6.5 are set to "container" which exposes a URI that can be accessed without authentication on the public internet. Access to the URI string requires privileged access to the Kubernetes cluster or authenticated access to the Azure portal.

CVSS3: 6.5
debian
почти 8 лет назад

Default access permissions for Persistent Volumes (PVs) created by the ...

CVSS3: 6.5
github
около 3 лет назад

Default access permissions for Persistent Volumes (PVs) created by the Kubernetes Azure cloud provider in versions 1.6.0 to 1.6.5 are set to "container" which exposes a URI that can be accessed without authentication on the public internet. Access to the URI string requires privileged access to the Kubernetes cluster or authenticated access to the Azure portal.

EPSS

Процентиль: 58%
0.00368
Низкий

6.5 Medium

CVSS3

4 Medium

CVSS2

Дефекты

CWE-200