#VU22937 Insecure default permissions in Kubernetes - CVE-2019-11244
Published: November 22, 2019 / Updated: December 22, 2020
Kubernetes
Kubernetes
Description
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to insecure default permissions for cache files directory, specified by "-cache-dir" option . A local user in a non-default Kubernetes configuration gain gain read/write access to cache files and gain access to sensitive information or disrupt kubectl invocation.