In Kubernetes versions 1.5.x, 1.6.x, 1.7.x, 1.8.x, and prior to version 1.9.6, the kubectl cp command insecurely handles tar data returned from the container, and can be caused to overwrite arbitrary local files.
CVSS Details
- CVSS 3.1 Base Score: 5.5
- CVSS 3.0 Base Score: 4.2
- CVSS 3.0 Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade kubernetes | Jul 30, 2024 | Jun 2, 2018 |
| Kubernetes | — | Upgrade Kubernetes to version 1.9.6 | Nov 13, 2018 | Jun 1, 2018 |
| Redhat Openshift | — | Upgrade atomic-openshift-web-consoleUpgrade openshift-ansibleUpgrade atomic-openshiftUpgrade rubygem-fluent-plugin-kubernetes_metadata_filterUpgrade cri-oUpgrade cri-toolsUpgrade rubygem-fluent-plugin-elasticsearchUpgrade atomic-openshift-dockerregistryUpgrade golang-github-prometheus-node_exporter | Oct 8, 2019 | Mar 17, 2018 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Jun 2, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub