PT-2019-12210 · Kubernetes+1 · Kubernetes+1
Jordan Zebor
+1
·
Published
2019-04-22
·
Updated
2022-02-15
·
CVE-2019-11244
CVSS v3.1
5.0
Medium
| Vector | AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Kubernetes versions 1.8.x through 1.14.x
Description
The issue concerns the caching of schema information by kubectl, which is written with world-writeable permissions. If the cache directory is specified and located in a place accessible to other users or groups, the cached files can be modified, potentially disrupting kubectl operations. The cache directory defaults to $HOME/.kube/http-cache, but can be changed using the
--cache-dir option.Recommendations
For Kubernetes versions 1.8.x through 1.14.x, consider restricting access to the cache directory to prevent modifications by other users or groups. As a temporary workaround, avoid using a cache directory that is accessible to other users or groups.
Exploit
Fix
Incorrect Permission
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Kubernetes