6.4
CVSSv2

CVE-2015-5305

Published: 06/11/2015 Updated: 13/02/2023
CVSS v2 Base Score: 6.4 | Impact Score: 4.9 | Exploitability Score: 10
VMScore: 570
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:P

Vulnerability Summary

Directory traversal vulnerability in Kubernetes, as used in Red Hat OpenShift Enterprise 3.0, allows malicious users to write to arbitrary files via a crafted object type name, which is not properly handled before passing it to etcd.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

redhat openshift 3.0

Vendor Advisories

Kubernetes fails to validate object name types before passing the data to etcd As the etcd service generates keys based on the object name type this can lead to a directory path traversal ...