← Back

CVE-2018-1002105

nvd nist
Published: Dec 5, 2018Modified: Nov 21, 2024

JSON object

Loading...
9.8
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD

Description

In all Kubernetes versions prior to v1.10.11, v1.11.5, and v1.12.3, incorrect handling of error responses to proxied upgrade requests in the kube-apiserver allowed specially crafted requests to establish a connection through the Kubernetes API server to backend servers, then send arbitrary requests over the same connection directly to the backend, authenticated with the Kubernetes API server's TLS credentials used to establish the backend connection.

Affected (14)

1 product
Kubernetes
1 product
Openshift Container Platform
1 product
Trident
Configuration A
5 vulnerable
Vulnerable SoftwareAffected Versions
Kubernetes
From 1.0.0 to 1.9.11
From 1.10.0 to 1.10.10
From 1.11.0 to 1.11.4
From 1.12.0 to 1.12.2
Version 1.9.12 beta0
Configuration B
8 vulnerable
Configuration C
1 vulnerable
Vulnerable SoftwareAffected Versions
All versions

Related CWEs

References (40)

Source: jordan@liggitt.net
Third Party AdvisoryVDB Entry
Source: jordan@liggitt.net
Third Party Advisory
Source: jordan@liggitt.net
Third Party Advisory
Source: jordan@liggitt.net
Third Party Advisory
Source: jordan@liggitt.net
Third Party Advisory
Source: jordan@liggitt.net
Third Party Advisory
Source: jordan@liggitt.net
Third Party Advisory
Source: jordan@liggitt.net
Third Party Advisory
Source: jordan@liggitt.net
Third Party Advisory
Source: jordan@liggitt.net
ExploitThird Party Advisory
Source: jordan@liggitt.net
Issue TrackingMitigationPatchThird Party Advisory
Source: jordan@liggitt.net
Third Party Advisory
Source: jordan@liggitt.net
ExploitThird Party AdvisoryVDB Entry
Source: jordan@liggitt.net
ExploitThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingMitigationPatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
MitigationThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party AdvisoryVDB Entry

Timeline

No history available yet.