Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2018-4303

Опубликовано: 11 дек. 2018
Источник: oracle-oval
Платформа: Oracle Linux 7

Описание

ELSA-2018-4303: kubernetes security update (IMPORTANT)

[1.9.11-2.1.1]

  • Fix kubeadm-registry.sh
  • Use golang 1.9.3
  • [CVE-2018-1002105] Handle error responses from backends
  • Bump to v1.9.11

Обновленные пакеты

Oracle Linux 7

Oracle Linux x86_64

kubeadm

1.9.11-2.1.1.el7

kubectl

1.9.11-2.1.1.el7

kubelet

1.9.11-2.1.1.el7

Связанные CVE

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 6 лет назад

In all Kubernetes versions prior to v1.10.11, v1.11.5, and v1.12.3, incorrect handling of error responses to proxied upgrade requests in the kube-apiserver allowed specially crafted requests to establish a connection through the Kubernetes API server to backend servers, then send arbitrary requests over the same connection directly to the backend, authenticated with the Kubernetes API server's TLS credentials used to establish the backend connection.

CVSS3: 9.8
redhat
больше 6 лет назад

In all Kubernetes versions prior to v1.10.11, v1.11.5, and v1.12.3, incorrect handling of error responses to proxied upgrade requests in the kube-apiserver allowed specially crafted requests to establish a connection through the Kubernetes API server to backend servers, then send arbitrary requests over the same connection directly to the backend, authenticated with the Kubernetes API server's TLS credentials used to establish the backend connection.

CVSS3: 9.8
nvd
больше 6 лет назад

In all Kubernetes versions prior to v1.10.11, v1.11.5, and v1.12.3, incorrect handling of error responses to proxied upgrade requests in the kube-apiserver allowed specially crafted requests to establish a connection through the Kubernetes API server to backend servers, then send arbitrary requests over the same connection directly to the backend, authenticated with the Kubernetes API server's TLS credentials used to establish the backend connection.

CVSS3: 9.8
debian
больше 6 лет назад

In all Kubernetes versions prior to v1.10.11, v1.11.5, and v1.12.3, in ...

CVSS3: 9.8
github
больше 3 лет назад

Privilege Escalation in Kubernetes