← Back

CVE-2017-1002102

nvd nist
Published: Mar 13, 2018Modified: Nov 21, 2024

JSON object

Loading...
5.6
Vector
CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:C/C:N/I:H/A:N
Exploitability: 1.1 / Impact: 4.0
Source: NVD

Description

In Kubernetes versions 1.3.x, 1.4.x, 1.5.x, 1.6.x and prior to versions 1.7.14, 1.8.9 and 1.9.4 containers using a secret, configMap, projected or downwardAPI volume can trigger deletion of arbitrary files/directories from the nodes where they are running.

Affected (7)

1 product
Kubernetes
Configuration A
7 vulnerable
Vulnerable SoftwareAffected Versions
Kubernetes
From 1.3.0 to 1.3.10
From 1.4.0 to 1.4.12
From 1.5.0 to 1.5.8
From 1.6.0 to 1.6.13
From 1.7.0 to 1.7.14
From 1.8.0 to 1.8.9
From 1.9.0 to 1.9.4

References (4)

Source: jordan@liggitt.net
Third Party Advisory
Source: jordan@liggitt.net
Issue TrackingVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingVendor Advisory

Timeline

No history available yet.