409
VMScore

CVE-2019-11245

Published: 29/08/2019 Updated: 19/09/2019
CVSS v2 Base Score: 4.6 | Impact Score: 6.4 | Exploitability Score: 3.9
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 409
Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

In kubelet v1.13.6 and v1.14.2, containers for pods that do not specify an explicit runAsUser attempt to run as uid 0 (root) on container restart, or if the image was previously pulled to the node. If the pod specified mustRunAsNonRoot: true, the kubelet will refuse to start the container as root. If the pod did not specify mustRunAsNonRoot: true, the kubelet will run the container as uid 0.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

kubernetes kubernetes 1.13.6

kubernetes kubernetes 1.14.2

Mailing Lists

Hello Kubernetes Community- A security-related issue was discovered in kubelet versions v1136 and v1142 The issue is medium severity and can be mitigated with a pod spec configuration change OR by *****downgrading*** kubelets to v1135 or v1141 ***Vulnerability Details*** When a container runs for the first time on a node, it correctly ...
Just in case anybody missed it explicitly…v1137 and v1143 were released yesterday, including the change for this CVE -- Tim Pepper Orchestration & Containers Lead VMware Open Source Technology Center From: <kubernetes-dev () googlegroups com> on behalf of Brandon Philips <bphilips () redhat com> Date: Thursday, May 30, 201 ...

Github Repositories

[WIP]ft_services

ft_services Requirement Usage Mac /srcs/ftps/ftpsyaml -> 1921689910 /srcs/metallb/metallbyaml -> 1921689910-1921689915 /srcs/wordpress/wordpressyaml -> "1921689910:5050" /srcs/srcs/nginx/srcs/indexhtml -> 1921689910 Linux /srcs/ftps/ftpsyaml -> 1921684910 /srcs/metallb/metallbyaml -> 192168