Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2017-1002102

Опубликовано: 06 мар. 2018
Источник: redhat
CVSS3: 7.1

Описание

In Kubernetes versions 1.3.x, 1.4.x, 1.5.x, 1.6.x and prior to versions 1.7.14, 1.8.9 and 1.9.4 containers using a secret, configMap, projected or downwardAPI volume can trigger deletion of arbitrary files/directories from the nodes where they are running.

This vulnerability allows containers using a secret, configMap, projected, or downwardAPI volume to trigger deletion of arbitrary files and directories on the nodes where they are running. An attacker could use this flaw to delete arbitrary file or directories on node host.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 7kubernetesWill not fix
Red Hat Storage 3heketiNot affected
Red Hat OpenShift Container Platform 3.3atomic-openshiftFixedRHSA-2018:047512.03.2018
Red Hat OpenShift Container Platform 3.4atomic-openshiftFixedRHSA-2018:047512.03.2018
Red Hat OpenShift Container Platform 3.5atomic-openshiftFixedRHSA-2018:047512.03.2018
Red Hat OpenShift Container Platform 3.6atomic-openshiftFixedRHSA-2018:047512.03.2018
Red Hat OpenShift Container Platform 3.7atomic-openshiftFixedRHSA-2018:047512.03.2018

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-59
https://bugzilla.redhat.com/show_bug.cgi?id=1551818kubernetes: Malicious containers can delete any file from the node

7.1 High

CVSS3

Связанные уязвимости

CVSS3: 7.1
nvd
больше 7 лет назад

In Kubernetes versions 1.3.x, 1.4.x, 1.5.x, 1.6.x and prior to versions 1.7.14, 1.8.9 and 1.9.4 containers using a secret, configMap, projected or downwardAPI volume can trigger deletion of arbitrary files/directories from the nodes where they are running.

CVSS3: 7.1
debian
больше 7 лет назад

In Kubernetes versions 1.3.x, 1.4.x, 1.5.x, 1.6.x and prior to version ...

CVSS3: 5.6
github
около 3 лет назад

Kubernetes arbitrary file overwrite

oracle-oval
около 7 лет назад

ELSA-2018-4061: kubernetes security update (IMPORTANT)

7.1 High

CVSS3