PT-2018-9619 · Kubernetes · Kubernetes

Michael Hanselmann

·

Published

2018-06-01

·

Updated

2025-08-08

·

CVE-2018-1002100

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions: Kubernetes versions 1.5.x through 1.9.5
Description: The issue concerns the insecure handling of tar data by the kubectl cp command, which can lead to the overwrite of arbitrary local files. This is a result of how the command manages data returned from the container.
Recommendations: For versions 1.5.x through 1.9.5, consider updating to a version that includes the fix for this issue, specifically version 1.9.6 or later, to prevent the insecure handling of tar data and potential overwrite of local files. As a temporary workaround, restrict the use of the kubectl cp command until a patch is applied.

Fix

RCE

Weakness Enumeration

Related Identifiers

CVE-2018-1002100
GHSA-2JQ6-FFPH-P4H8
GO-2023-1959
OPENSUSE-SU-2025:15424-1

Affected Products

Kubernetes