CVE Vulnerabilities

CVE-2017-1002102

Published: Mar 13, 2018 | Modified: Oct 09, 2019
CVSS 3.x
5.6
MEDIUM
Source:
NVD
CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:C/C:N/I:H/A:N
CVSS 2.x
6.3 MEDIUM
AV:L/AC:M/Au:N/C:N/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu

In Kubernetes versions 1.3.x, 1.4.x, 1.5.x, 1.6.x and prior to versions 1.7.14, 1.8.9 and 1.9.4 containers using a secret, configMap, projected or downwardAPI volume can trigger deletion of arbitrary files/directories from the nodes where they are running.

Affected Software

Name Vendor Start Version End Version
Kubernetes Kubernetes 1.3.0 (including) 1.3.10 (including)
Kubernetes Kubernetes 1.4.0 (including) 1.4.12 (including)
Kubernetes Kubernetes 1.5.0 (including) 1.5.8 (including)
Kubernetes Kubernetes 1.6.0 (including) 1.6.13 (including)
Kubernetes Kubernetes 1.7.0 (including) 1.7.14 (excluding)
Kubernetes Kubernetes 1.8.0 (including) 1.8.9 (excluding)
Kubernetes Kubernetes 1.9.0 (including) 1.9.4 (excluding)

References