CVE-2019-11244

Related Vulnerabilities: CVE-2019-11244  

Impact: Low Public Date: 2019-04-22 CWE: CWE-732 Bugzilla: 1703209: CVE-2019-11244 kubernetes: Schema info written with world-writeable permissions when cached In Kubernetes v1.8.x-v1.14.x, schema info is cached by kubectl in the location specified by --cache-dir (defaulting to $HOME/.kube/http-cache), written with world-writeable permissions (rw-rw-rw-). If --cache-dir is specified and pointed at a different location accessible to other users/groups, the written files may be modified by other users/groups and disrupt the kubectl invocation.

The MITRE CVE dictionary describes this issue as:

In Kubernetes v1.8.x-v1.14.x, schema info is cached by kubectl in the location specified by --cache-dir (defaulting to $HOME/.kube/http-cache), written with world-writeable permissions (rw-rw-rw-). If --cache-dir is specified and pointed at a different location accessible to other users/groups, the written files may be modified by other users/groups and disrupt the kubectl invocation.

Find out more about CVE-2019-11244 from the MITRE CVE dictionary dictionary and NIST NVD.

CVSS v3 metrics

NOTE: The following CVSS v3 metrics and score provided are preliminary and subject to review.

CVSS3 Base Score 3.3
CVSS3 Base Metrics CVSS:3.0/AV:L/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:N
Attack Vector Local
Attack Complexity High
Privileges Required Low
User Interaction Required
Scope Unchanged
Confidentiality Low
Integrity Impact Low
Availability Impact None

Affected Packages State

Platform Package State
Red Hat OpenShift Container Platform 3.9 atomic-openshift Under investigation
Red Hat OpenShift Container Platform 3.7 atomic-openshift Under investigation
Red Hat OpenShift Container Platform 3.6 atomic-openshift Under investigation
Red Hat OpenShift Container Platform 3.5 atomic-openshift Under investigation
Red Hat OpenShift Container Platform 3.4 atomic-openshift Under investigation
Red Hat OpenShift Container Platform 3.11 atomic-openshift Under investigation
Red Hat OpenShift Container Platform 3.10 atomic-openshift Under investigation
Red Hat Gluster Storage 3 heketi Under investigation
Red Hat Enterprise Linux 7 containernetworking-plugins Under investigation