PT-2018-9619 · Kubernetes · Kubernetes
Michael Hanselmann
·
Published
2018-06-01
·
Updated
2025-08-08
·
CVE-2018-1002100
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions:
Kubernetes versions 1.5.x through 1.9.5
Description:
The issue concerns the insecure handling of tar data by the kubectl cp command, which can lead to the overwrite of arbitrary local files. This is a result of how the command manages data returned from the container.
Recommendations:
For versions 1.5.x through 1.9.5, consider updating to a version that includes the fix for this issue, specifically version 1.9.6 or later, to prevent the insecure handling of tar data and potential overwrite of local files. As a temporary workaround, restrict the use of the kubectl cp command until a patch is applied.
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Kubernetes