PT-2018-9619 · Kubernetes · Kubernetes

·

CVE-2018-1002100

·

Publicado

2018-06-01

·

Atualizado

2025-08-08

CVSS v3.1

5.5

Média

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions: Kubernetes versions 1.5.x through 1.9.5
Description: The issue concerns the insecure handling of tar data by the kubectl cp command, which can lead to the overwrite of arbitrary local files. This is a result of how the command manages data returned from the container.
Recommendations: For versions 1.5.x through 1.9.5, consider updating to a version that includes the fix for this issue, specifically version 1.9.6 or later, to prevent the insecure handling of tar data and potential overwrite of local files. As a temporary workaround, restrict the use of the kubectl cp command until a patch is applied.

Correção

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-1002100
GHSA-2JQ6-FFPH-P4H8
GO-2023-1959
OPENSUSE-SU-2025:15424-1

Produtos afetados

Kubernetes