5.6
CVSSv3

CVE-2017-1002102

Published: 13/03/2018 Updated: 09/10/2019
CVSS v2 Base Score: 6.3 | Impact Score: 9.2 | Exploitability Score: 3.4
CVSS v3 Base Score: 5.6 | Impact Score: 4 | Exploitability Score: 1.1
VMScore: 562
Vector: AV:L/AC:M/Au:N/C:N/I:C/A:C

Vulnerability Summary

In Kubernetes versions 1.3.x, 1.4.x, 1.5.x, 1.6.x and prior to versions 1.7.14, 1.8.9 and 1.9.4 containers using a secret, configMap, projected or downwardAPI volume can trigger deletion of arbitrary files/directories from the nodes where they are running.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

kubernetes kubernetes

Vendor Advisories

Synopsis Important: Red Hat OpenShift Container Platform security update Type/Severity Security Advisory: Important Topic An update is now available for Red Hat OpenShift Container Platform 37, 36, 35, 34, and 33Red Hat Product Security has rated this update as having a security impact of Important A ...
Debian Bug report logs - #892801 kubernetes: CVE-2017-1002101: Volume security can be sidestepped with innocent emptyDir and subpath Package: src:kubernetes; Maintainer for src:kubernetes is Dmitry Smirnov <onlyjob@debianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Tue, 13 Mar 2018 07:15:02 UTC ...
Debian Bug report logs - #894051 kubernetes: CVE-2017-1002102 Package: src:kubernetes; Maintainer for src:kubernetes is Dmitry Smirnov <onlyjob@debianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Sun, 25 Mar 2018 20:21:02 UTC Severity: grave Tags: fixed-upstream, patch, security, upstream Found ...
This vulnerability allows containers using a secret, configMap, projected, or downwardAPI volume to trigger deletion of arbitrary files and directories on the nodes where they are running An attacker could use this flaw to delete arbitrary file or directories on node host ...