CVE-2018-1002101

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
05/12/2018
Last modified:
09/10/2019

Description

In Kubernetes versions 1.9.0-1.9.9, 1.10.0-1.10.5, and 1.11.0-1.11.1, user input was handled insecurely while setting up volume mounts on Windows nodes, which could lead to command line argument injection.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:kubernetes:kubernetes:*:*:*:*:*:*:*:* 1.9.0 (including) 1.9.9 (including)
cpe:2.3:a:kubernetes:kubernetes:*:*:*:*:*:*:*:* 1.10.0 (including) 1.10.5 (including)
cpe:2.3:a:kubernetes:kubernetes:*:*:*:*:*:*:*:* 1.11.0 (including) 1.11.1 (including)