VulnerabilityModified
CVE-2018-1002100
In Kubernetes versions 1.5.x, 1.6.x, 1.7.x, 1.8.x, and prior to version 1.9.6, the kubectl cp command insecurely handles tar data returned from the container, and can be caused to overwrite arbitrary local files.
MEDIUM 5.5EPSS 1.59%
Does this matter?
Lower severity and a low EPSS score (1.59%). Track it; it rarely justifies an emergency change on its own.
Description
In Kubernetes versions 1.5.x, 1.6.x, 1.7.x, 1.8.x, and prior to version 1.9.6, the kubectl cp command insecurely handles tar data returned from the container, and can be caused to overwrite arbitrary local files.
- CVSS 3.0
- 5.5 MEDIUMCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
- EPSS
- 1.59% probability · 74th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20
- Affected
- kubernetes/kubernetes
- Source
- jordan@liggitt.net
References
- https://bugzilla.redhat.com/show_bug.cgi?id=1564305Issue Tracking, Third Party Advisory
- https://github.com/kubernetes/kubernetes/issues/61297Third Party Advisory
- https://hansmi.ch/articles/2018-04-openshift-s2i-securityThird Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1564305Issue Tracking, Third Party Advisory
- https://github.com/kubernetes/kubernetes/issues/61297Third Party Advisory
- https://hansmi.ch/articles/2018-04-openshift-s2i-securityThird Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.