CVE Vulnerabilities

CVE-2018-1002101

Published: Dec 05, 2018 | Modified: Nov 21, 2024
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
7 MODERATE
CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Ubuntu
root.io logo minimus.io logo echo.ai logo

In Kubernetes versions 1.9.0-1.9.9, 1.10.0-1.10.5, and 1.11.0-1.11.1, user input was handled insecurely while setting up volume mounts on Windows nodes, which could lead to command line argument injection.

Affected Software

NameVendorStart VersionEnd Version
KubernetesKubernetes1.9.0 (including)1.9.9 (including)
KubernetesKubernetes1.10.0 (including)1.10.5 (including)
KubernetesKubernetes1.11.0 (including)1.11.1 (including)

References