CVE-2017-1002101

Severity CVSS v4.0:
Pending analysis
Type:
CWE-59 Link Following
Publication date:
13/03/2018
Last modified:
09/10/2019

Description

In Kubernetes versions 1.3.x, 1.4.x, 1.5.x, 1.6.x and prior to versions 1.7.14, 1.8.9 and 1.9.4 containers using subpath volume mounts with any volume type (including non-privileged pods, subject to file permissions) can access files/directories outside of the volume, including the host's filesystem.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:kubernetes:kubernetes:*:*:*:*:*:*:*:* 1.3.0 (including) 1.3.10 (including)
cpe:2.3:a:kubernetes:kubernetes:*:*:*:*:*:*:*:* 1.4.0 (including) 1.4.12 (including)
cpe:2.3:a:kubernetes:kubernetes:*:*:*:*:*:*:*:* 1.5.0 (including) 1.5.8 (including)
cpe:2.3:a:kubernetes:kubernetes:*:*:*:*:*:*:*:* 1.6.0 (including) 1.6.13 (including)
cpe:2.3:a:kubernetes:kubernetes:*:*:*:*:*:*:*:* 1.7.0 (including) 1.7.14 (excluding)
cpe:2.3:a:kubernetes:kubernetes:*:*:*:*:*:*:*:* 1.8.0 (including) 1.8.9 (excluding)
cpe:2.3:a:kubernetes:kubernetes:*:*:*:*:*:*:*:* 1.9.0 (including) 1.9.4 (excluding)