Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2018-1002100


In Kubernetes versions 1.5.x, 1.6.x, 1.7.x, 1.8.x, and prior to version 1.9.6, the kubectl cp command insecurely handles tar data returned from the container, and can be caused to overwrite arbitrary local files.


Published

2018-06-02T01:29:02.110

Last Modified

2024-11-21T03:40:38.253

Status

Modified

Source

[email protected]

Severity

CVSSv3.0: 4.2 (MEDIUM)

CVSSv2 Vector

AV:L/AC:L/Au:N/C:N/I:P/A:P

  • Access Vector: LOCAL
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: NONE
  • Integrity Impact: PARTIAL
  • Availability Impact: PARTIAL
Exploitability Score

3.9

Impact Score

4.9

Weaknesses
  • Type: Primary
    CWE-20

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application kubernetes kubernetes ≤ 1.5.9 Yes
Application kubernetes kubernetes ≤ 1.6.14 Yes
Application kubernetes kubernetes ≤ 1.7.17 Yes
Application kubernetes kubernetes ≤ 1.8.15 Yes
Application kubernetes kubernetes ≤ 1.9.5 Yes

References