Kubernetes arbitrary file overwrite in k8s.io/kubernetes
Kubernetes arbitrary file overwrite in k8s.io/kubernetes
02 / AFFECTED SOFTWARE
Affected packages
42 explicit affected versions
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
Kubernetes arbitrary file overwrite in k8s.io/kubernetes
In Kubernetes versions 1.5.x, 1.6.x, 1.7.x, 1.8.x, and prior to version 1.9.6, the kubectl cp command insecurely handles tar data returned from the container, and can be caused to overwrite arbitrary local files.
In Kubernetes versions 1.5.x, 1.6.x, 1.7.x, 1.8.x, and prior to version 1.9.6, the kubectl cp command insecurely handles tar data returned from the container, and can be caused to overwrite arbitrary local files.
05 / REFERENCES
Further evidence
- https://bugzilla.redhat.com/show_bug.cgi?id=1564305
- https://github.com/advisories/GHSA-2jq6-ffph-p4h8
- https://github.com/kubernetes/kubernetes/issues/61297
- https://hansmi.ch/articles/2018-04-openshift-s2i-security
- https://github.com/kubernetes/kubernetes
- https://nvd.nist.gov/vuln/detail/CVE-2018-1002100