← Back

CVE-2019-11244

nvd nist
Published: Apr 22, 2019Modified: Jun 17, 2026

JSON object

Loading...
5.0
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:N
Exploitability: 1.3 / Impact: 3.6
Source: NVD

Description

In Kubernetes v1.8.x-v1.14.x, schema info is cached by kubectl in the location specified by --cache-dir (defaulting to $HOME/.kube/http-cache), written with world-writeable permissions (rw-rw-rw-). If --cache-dir is specified and pointed at a different location accessible to other users/groups, the written files may be modified by other users/groups and disrupt the kubectl invocation.

Affected (4)

1 product
Kubernetes
1 product
Trident
1 product
Openshift Container Platform
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
From 1.8.0 to 1.14.1
Configuration B
1 vulnerable
Vulnerable SoftwareAffected Versions
All versions
Configuration C
2 vulnerable
Vulnerable SoftwareAffected Versions
Redhat
Version 3.11
Version 4.1

References (12)

Source: jordan@liggitt.net
Third Party AdvisoryVDB Entry
Source: jordan@liggitt.net
Third Party Advisory
Source: jordan@liggitt.net
Third Party Advisory
Source: jordan@liggitt.net
Third Party Advisory
Source: jordan@liggitt.net
Third Party Advisory
Source: jordan@liggitt.net
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory

Timeline

No history available yet.