Information disclosure in Kubernetes - CVE-2017-1002101
Published: March 16, 2018
Vulnerability identifier: #VU11127
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-1002101
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote authenticated attacker to obtain potentially sensitive information on the target system.
The weakness exists due to improper security restrictions when using subpath volume mounts with any volume type. A remote attacker can gain unauthorized access to files and directories.
The weakness exists due to improper security restrictions when using subpath volume mounts with any volume type. A remote attacker can gain unauthorized access to files and directories.
Affected software
Kubernetes
Red Hat OpenShift Container Platform
Opensuse
Fedora
kubernetes
origin
Red Hat OpenShift Container Platform
Opensuse
Fedora
kubernetes
origin
How to mitigate CVE-2017-1002101
Update to versions 1.7.14, 1.8.9 or 1.9.4.
kubernetes - addressed in versions 1.10.1-0.fc27, 1.10.1-0.fc28
origin - update to 3.9.0-1.fc28
origin - update to 3.9.0-1.fc28