PT-2018-9619 · Kubernetes · Kubernetes
CVSS v3.1
5.5
Média
| Vetor | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions:
Kubernetes versions 1.5.x through 1.9.5
Description:
The issue concerns the insecure handling of tar data by the kubectl cp command, which can lead to the overwrite of arbitrary local files. This is a result of how the command manages data returned from the container.
Recommendations:
For versions 1.5.x through 1.9.5, consider updating to a version that includes the fix for this issue, specifically version 1.9.6 or later, to prevent the insecure handling of tar data and potential overwrite of local files. As a temporary workaround, restrict the use of the kubectl cp command until a patch is applied.
Correção
RCE
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Kubernetes