5.5
CVSSv3

CVE-2018-1002100

Published: 02/06/2018 Updated: 09/10/2019
CVSS v2 Base Score: 3.6 | Impact Score: 4.9 | Exploitability Score: 3.9
CVSS v3 Base Score: 5.5 | Impact Score: 3.6 | Exploitability Score: 1.8
VMScore: 322
Vector: AV:L/AC:L/Au:N/C:N/I:P/A:P

Vulnerability Summary

In Kubernetes versions 1.5.x, 1.6.x, 1.7.x, 1.8.x, and prior to version 1.9.6, the kubectl cp command insecurely handles tar data returned from the container, and can be caused to overwrite arbitrary local files.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

kubernetes kubernetes

Vendor Advisories

Debian Bug report logs - #929225 kubernetes: CVE-2018-1002100 Package: src:kubernetes; Maintainer for src:kubernetes is Dmitry Smirnov <onlyjob@debianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Sun, 19 May 2019 15:30:01 UTC Severity: grave Tags: fixed-upstream, security, upstream Found in vers ...
An improper validation flaw exists in the kubernetes 'kubectl cp' command An attacker who could trick a user into using the command to copy files locally, from a pod, could override files outside of the target directory of the command ...