CVE-2018-18264

Severity CVSS v4.0:
Pending analysis
Type:
CWE-306 Missing Authentication for Critical Function
Publication date:
03/01/2019
Last modified:
07/11/2023

Description

Kubernetes Dashboard before 1.10.1 allows attackers to bypass authentication and use Dashboard's Service Account for reading secrets within the cluster.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:kubernetes:dashboard:*:*:*:*:*:*:*:* 1.10.1 (excluding)