← Back

CVE-2019-11251

nvd nist
Published: Feb 3, 2020Modified: Jun 17, 2026

JSON object

Loading...
5.7
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:N
Exploitability: 2.1 / Impact: 3.6
Source: NVD

Description

The Kubernetes kubectl cp command in versions 1.1-1.12, and versions prior to 1.13.11, 1.14.7, and 1.15.4 allows a combination of two symlinks provided by tar output of a malicious container to place a file outside of the destination directory specified in the kubectl cp invocation. This could be used to allow an attacker to place a nefarious file using a symlink, outside of the destination tree.

Affected (4)

1 product
Kubernetes
Configuration A
4 vulnerable
Vulnerable SoftwareAffected Versions
Kubernetes
From 1.13.0 to 1.13.11
From 1.14.0 to 1.14.7
From 1.15.0 to 1.15.4
Version 1.1-1.12

References (4)

Source: jordan@liggitt.net
Third Party Advisory
Source: jordan@liggitt.net
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory

Timeline

No history available yet.