Impact: Low Public Date: 2019-04-22 CWE: CWE-732 Bugzilla: 1703209: CVE-2019-11244 kubernetes: Schema info written with world-writeable permissions when cached In Kubernetes v1.8.x-v1.14.x, schema info is cached by kubectl in the location specified by --cache-dir (defaulting to $HOME/.kube/http-cache), written with world-writeable permissions (rw-rw-rw-). If --cache-dir is specified and pointed at a different location accessible to other users/groups, the written files may be modified by other users/groups and disrupt the kubectl invocation.
The MITRE CVE dictionary describes this issue as:
Find out more about CVE-2019-11244 from the MITRE CVE dictionary dictionary and NIST NVD.
NOTE: The following CVSS v3 metrics and score provided are preliminary and subject to review.
CVSS3 Base Score | 3.3 |
---|---|
CVSS3 Base Metrics | CVSS:3.0/AV:L/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:N |
Attack Vector | Local |
Attack Complexity | High |
Privileges Required | Low |
User Interaction | Required |
Scope | Unchanged |
Confidentiality | Low |
Integrity Impact | Low |
Availability Impact | None |
Platform | Package | State |
---|---|---|
Red Hat OpenShift Container Platform 3.9 | atomic-openshift | Under investigation |
Red Hat OpenShift Container Platform 3.7 | atomic-openshift | Under investigation |
Red Hat OpenShift Container Platform 3.6 | atomic-openshift | Under investigation |
Red Hat OpenShift Container Platform 3.5 | atomic-openshift | Under investigation |
Red Hat OpenShift Container Platform 3.4 | atomic-openshift | Under investigation |
Red Hat OpenShift Container Platform 3.11 | atomic-openshift | Under investigation |
Red Hat OpenShift Container Platform 3.10 | atomic-openshift | Under investigation |
Red Hat Gluster Storage 3 | heketi | Under investigation |
Red Hat Enterprise Linux 7 | containernetworking-plugins | Under investigation |