Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-11244

Опубликовано: 22 апр. 2019
Источник: redhat
CVSS3: 3.3
EPSS Низкий

Описание

In Kubernetes v1.8.x-v1.14.x, schema info is cached by kubectl in the location specified by --cache-dir (defaulting to $HOME/.kube/http-cache), written with world-writeable permissions (rw-rw-rw-). If --cache-dir is specified and pointed at a different location accessible to other users/groups, the written files may be modified by other users/groups and disrupt the kubectl invocation.

A flaw was found in kubectl that leaves http-cache files with read/write permissions for any user. In conjunction with a non-default value for --cache-dir, this may lead to the cache content being placed in a location accessible to other users on the system.

Отчет

OpenShift Container Platform includes kubectl. OCP 3.9 and later include this same flaw. This issue does not affect the version of Kubernetes (embedded in heketi) shipped with Red Hat Gluster Storage 3 as it does not contain the vulnerable functionality.

Меры по смягчению последствий

Do not use --cache-dir, or ensure that --cache-dir is not set to a location that other users have access to.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenShift Container Platform 3.10atomic-openshiftAffected
Red Hat OpenShift Container Platform 3.6atomic-openshiftNot affected
Red Hat OpenShift Container Platform 3.7atomic-openshiftNot affected
Red Hat OpenShift Container Platform 3.9atomic-openshiftAffected
Red Hat Storage 3heketiNot affected
Red Hat OpenShift Container Platform 3.11atomic-openshiftFixedRHSA-2020:002014.01.2020
Red Hat OpenShift Container Platform 4.1openshiftFixedRHSA-2019:394221.11.2019
Red Hat OpenShift Container Platform 4.1openshift4/ose-cliFixedRHSA-2020:007421.01.2020

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-732
https://bugzilla.redhat.com/show_bug.cgi?id=1703209kubernetes: Schema info written with world-writeable permissions when cached

EPSS

Процентиль: 29%
0.00102
Низкий

3.3 Low

CVSS3

Связанные уязвимости

CVSS3: 5
nvd
около 6 лет назад

In Kubernetes v1.8.x-v1.14.x, schema info is cached by kubectl in the location specified by --cache-dir (defaulting to $HOME/.kube/http-cache), written with world-writeable permissions (rw-rw-rw-). If --cache-dir is specified and pointed at a different location accessible to other users/groups, the written files may be modified by other users/groups and disrupt the kubectl invocation.

CVSS3: 5
debian
около 6 лет назад

In Kubernetes v1.8.x-v1.14.x, schema info is cached by kubectl in the ...

CVSS3: 5
github
больше 3 лет назад

Kubernetes Unsafe Cacheing

oracle-oval
почти 6 лет назад

ELSA-2019-4717: kubeadm-ha-setup security update (IMPORTANT)

oracle-oval
почти 6 лет назад

ELSA-2019-4716: kubernetes security update (IMPORTANT)

EPSS

Процентиль: 29%
0.00102
Низкий

3.3 Low

CVSS3