Path traversal in Kubernetes - CVE-2018-1002100
Published: July 30, 2018 / Updated: July 30, 2018
Kubernetes
Detailed vulnerability description
The vulnerability allows a remote attacker to conduct path traversal attack on the target system.
The vulnerability exists due to the kubectl cp command insecurely handles tar data returned from the container. A remote unauthenticated attacker can conduct path traversal attack and overwrite arbitrary local files.