CVE-2017-1002101

All FrameworksKubernetesCWE-OtherCVE-2017-1002101

CVE-2017-1002101

State: PUBLISHED · Published: 2018-03-13 · Updated: 2024-08-05 · Assigner: kubernetes
Description
In Kubernetes versions 1.3.x, 1.4.x, 1.5.x, 1.6.x and prior to versions 1.7.14, 1.8.9 and 1.9.4 containers using subpath volume mounts with any volume type (including non-privileged pods, subject to file permissions) can access files/directories outside of the volume, including the host's filesystem.
CWE
Affected
CVSS
References
Source
cvelistV5-main/cves/2017/1002xxx/CVE-2017-1002101.json