← Back

CVE-2018-1002102

nvd nist
Published: Dec 5, 2019Modified: Nov 21, 2024

JSON object

Loading...
2.6
Vector
CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:C/C:L/I:N/A:N
Exploitability: 1.0 / Impact: 1.4
Source: NVD

Description

Improper validation of URL redirection in the Kubernetes API server in versions prior to v1.14.0 allows an attacker-controlled Kubelet to redirect API server requests from streaming endpoints to arbitrary hosts. Impacted API servers will follow the redirect as a GET request with client-certificate credentials for authenticating to the Kubelet.

Affected (4)

1 product
Kubernetes
1 product
Fedora
Configuration A
3 vulnerable
Vulnerable SoftwareAffected Versions
Kubernetes
From 1.10.0 to 1.13.13
Version 1.14.0 alpha0
Version 1.14.0 alpha1
Configuration B
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 31

Timeline

No history available yet.