CVE-2017-1002101
In Kubernetes versions 1.3.x, 1.4.x, 1.5.x, 1.6.x and prior to versions 1.7.14, 1.8.9 and 1.9.4 containers using subpath volume mounts with any volume type (including non-privileged pods, subject to file permissions) can access files/directories outside…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 13.3%, higher than 96% of all known CVEs. Patch or mitigate before the next change window.
Description
In Kubernetes versions 1.3.x, 1.4.x, 1.5.x, 1.6.x and prior to versions 1.7.14, 1.8.9 and 1.9.4 containers using subpath volume mounts with any volume type (including non-privileged pods, subject to file permissions) can access files/directories outside of the volume, including the host's filesystem.
- CVSS 3.0
- 9.6 CRITICALCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N
- EPSS
- 13.27% probability · 96th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-59
- Affected
- kubernetes/kubernetes
- Source
- jordan@liggitt.net
References
- http://lists.opensuse.org/opensuse-security-announce/2020-04/msg00041.html
- https://access.redhat.com/errata/RHSA-2018:0475Third Party Advisory
- https://github.com/bgeesaman/subpath-exploit/Exploit, Third Party Advisory
- https://github.com/kubernetes/kubernetes/issues/60813Issue Tracking, Mitigation, Vendor Advisory
- http://lists.opensuse.org/opensuse-security-announce/2020-04/msg00041.html
- https://access.redhat.com/errata/RHSA-2018:0475Third Party Advisory
- https://github.com/bgeesaman/subpath-exploit/Exploit, Third Party Advisory
- https://github.com/kubernetes/kubernetes/issues/60813Issue Tracking, Mitigation, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.