CVE Vulnerabilities

CVE-2017-1002102

Published: Mar 13, 2018 | Modified: Nov 21, 2024
CVSS 3.x
5.6
MEDIUM
Source:
NVD
CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:C/C:N/I:H/A:N
CVSS 2.x
6.3 MEDIUM
AV:L/AC:M/Au:N/C:N/I:C/A:C
RedHat/V2
RedHat/V3
7.1 MODERATE
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

In Kubernetes versions 1.3.x, 1.4.x, 1.5.x, 1.6.x and prior to versions 1.7.14, 1.8.9 and 1.9.4 containers using a secret, configMap, projected or downwardAPI volume can trigger deletion of arbitrary files/directories from the nodes where they are running.

Affected Software

NameVendorStart VersionEnd Version
KubernetesKubernetes1.3.0 (including)1.3.10 (including)
KubernetesKubernetes1.4.0 (including)1.4.12 (including)
KubernetesKubernetes1.5.0 (including)1.5.8 (including)
KubernetesKubernetes1.6.0 (including)1.6.13 (including)
KubernetesKubernetes1.7.0 (including)1.7.14 (excluding)
KubernetesKubernetes1.8.0 (including)1.8.9 (excluding)
KubernetesKubernetes1.9.0 (including)1.9.4 (excluding)
Red Hat OpenShift Container Platform 3.3RedHatatomic-openshift-0:3.3.1.46.11-1.git.4.e236015.el7*
Red Hat OpenShift Container Platform 3.4RedHatatomic-openshift-0:3.4.1.44.38-1.git.4.bb8df08.el7*
Red Hat OpenShift Container Platform 3.5RedHatatomic-openshift-0:3.5.5.31.48-1.git.4.ff6153e.el7*
Red Hat OpenShift Container Platform 3.6RedHatatomic-openshift-0:3.6.173.0.96-1.git.4.e6301f8.el7*
Red Hat OpenShift Container Platform 3.7RedHatatomic-openshift-0:3.7.23-1.git.5.83efd71.el7*

References