CVE-2017-1002101
Description
In Kubernetes versions 1.3.x, 1.4.x, 1.5.x, 1.6.x and prior to versions 1.7.14, 1.8.9 and 1.9.4 containers using subpath volume mounts with any volume type (including non-privileged pods, subject to file permissions) can access files/directories outside of the volume, including the host's filesystem.
CWE
- (none)
Affected
- Kubernetes / Kubernetes — v=v1.3.x [affected]; v=v1.4.x [affected]; v=v1.5.x [affected]; v=v1.6.x [affected]; v=unspecified <v1.7.14 [affected]; v=unspecified <v1.8.9 [affected]; v=unspecified <v1.9.4 [affected]
CVSS
- 3.0 score=8.8 severity=HIGH
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
References
- https://access.redhat.com/errata/RHSA-2018:0475 vendor-advisory, x_refsource_REDHAT
- https://github.com/kubernetes/kubernetes/issues/60813 x_refsource_CONFIRM
- https://github.com/bgeesaman/subpath-exploit/ x_refsource_MISC
- http://lists.opensuse.org/opensuse-security-announce/2020-04/msg00041.html vendor-advisory, x_refsource_SUSE
Source
cvelistV5-main/cves/2017/1002xxx/CVE-2017-1002101.json