Описание
In Kubernetes versions 1.5.x, 1.6.x, 1.7.x, 1.8.x, and prior to version 1.9.6, the kubectl cp command insecurely handles tar data returned from the container, and can be caused to overwrite arbitrary local files.
An improper validation flaw exists in the kubernetes 'kubectl cp' command. An attacker, who could trick a user into using the command to copy files locally from a pod, could override files outside of the target directory of the command.
Отчет
Kubernetes support is moving from Red Hat Enterprise Linux to OpenShift Container Platform. Kubernetes and its dependencies will no longer be updated through the Extras channel. Instead, the Red Hat customers are advised to use Red Hat's supported Kubernetes-based products such as Red Hat OpenShift Container Platform.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
Red Hat Enterprise Linux 7 | kubernetes | Will not fix | ||
Red Hat OpenShift Container Platform 3.10 | atomic-openshift | Not affected | ||
Red Hat OpenShift Container Platform 3.11 | atomic-openshift | Not affected | ||
Red Hat OpenShift Container Platform 4 | openshift | Not affected | ||
Red Hat OpenShift Container Platform 3.9 | atomic-openshift | Fixed | RHBA-2018:1796 | 06.06.2018 |
Red Hat OpenShift Container Platform 3.9 | atomic-openshift-dockerregistry | Fixed | RHBA-2018:1796 | 06.06.2018 |
Red Hat OpenShift Container Platform 3.9 | atomic-openshift-web-console | Fixed | RHBA-2018:1796 | 06.06.2018 |
Red Hat OpenShift Container Platform 3.9 | cri-o | Fixed | RHBA-2018:1796 | 06.06.2018 |
Red Hat OpenShift Container Platform 3.9 | cri-tools | Fixed | RHBA-2018:1796 | 06.06.2018 |
Red Hat OpenShift Container Platform 3.9 | golang-github-prometheus-node_exporter | Fixed | RHBA-2018:1796 | 06.06.2018 |
Показывать по
Дополнительная информация
Статус:
6.1 Medium
CVSS3
Связанные уязвимости
In Kubernetes versions 1.5.x, 1.6.x, 1.7.x, 1.8.x, and prior to version 1.9.6, the kubectl cp command insecurely handles tar data returned from the container, and can be caused to overwrite arbitrary local files.
In Kubernetes versions 1.5.x, 1.6.x, 1.7.x, 1.8.x, and prior to version 1.9.6, the kubectl cp command insecurely handles tar data returned from the container, and can be caused to overwrite arbitrary local files.
In Kubernetes versions 1.5.x, 1.6.x, 1.7.x, 1.8.x, and prior to versio ...
6.1 Medium
CVSS3