FlawAtlas
Search the atlas
CVE-2018-1002100 Moderate

Kubernetes arbitrary file overwrite in k8s.io/kubernetes

Kubernetes arbitrary file overwrite in k8s.io/kubernetes

Exploit probability 1.6%
Published August 20, 2024
Required by Not available
Last source change March 3, 2026

02 / AFFECTED SOFTWARE

Affected packages

Unknown Unknown

42 explicit affected versions

Go k8s.io/kubernetes
Go k8s.io/kubernetes

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities GHSA-2jq6-ffph-p4h8

In Kubernetes versions 1.5.x, 1.6.x, 1.7.x, 1.8.x, and prior to version 1.9.6, the kubectl cp command insecurely handles tar data returned from the container, and can be caused to overwrite arbitrary local files.

View original source
Open Source Vulnerabilities CVE-2018-1002100

In Kubernetes versions 1.5.x, 1.6.x, 1.7.x, 1.8.x, and prior to version 1.9.6, the kubectl cp command insecurely handles tar data returned from the container, and can be caused to overwrite arbitrary local files.

View original source

05 / REFERENCES

Further evidence