6.5
CVSSv2

CVE-2018-1000400

Published: 18/05/2018 Updated: 03/10/2019
CVSS v2 Base Score: 6.5 | Impact Score: 6.4 | Exploitability Score: 8
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 578
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P

Vulnerability Summary

Kubernetes CRI-O version before 1.9 contains a Privilege Context Switching Error (CWE-270) vulnerability in the handling of ambient capabilities that can result in containers running with elevated privileges, allowing users abilities they should not have. This attack appears to be exploitable via container execution. This vulnerability appears to have been fixed in 1.9.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

kubernetes cri-o

Vendor Advisories

Kubernetes CRI-O version prior to 19 contains a Privilege Context Switching Error (CWE-270) vulnerability in the handling of ambient capabilities that can result in containers running with elevated privileges, allowing users abilities they should not have This attack appears to be exploitable via container execution This vulnerability appears to ...

Github Repositories

Cri-o research This research was carried out as part of an internship Summ3r of Hack in Dsec Crio is meant to provide an integration path between OCI conformant runtimes and the kubelet Specifically, it implements the Kubelet Container Runtime Interface (CRI) using OCI conformant runtimes The scope of crio is tied to the scope of the CRI Support multiple image formats in