In Kubernetes versions 1.5.x, 1.6.x, 1.7.x, 1.8.x, and prior to version 1.9.6, the kubectl cp command insecurely handles tar data returned from the container, and can be caused to overwrite arbitrary local files.
CVSS Details
- CVSS 3.1 Base Score: 5.5
- CVSS 3.0 Base Score: 4.2
- CVSS 3.0 Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade kubernetes | Jul 30, 2024 | Jun 2, 2018 |
| Kubernetes | — | Upgrade Kubernetes to version 1.9.6 | Nov 13, 2018 | Jun 1, 2018 |
| Redhat Openshift | — | Upgrade rubygem-fluent-plugin-elasticsearchUpgrade golang-github-prometheus-node_exporterUpgrade atomic-openshift-dockerregistryUpgrade atomic-openshiftUpgrade cri-oUpgrade atomic-openshift-web-consoleUpgrade rubygem-fluent-plugin-kubernetes_metadata_filterUpgrade openshift-ansibleUpgrade cri-tools | Oct 8, 2019 | Mar 17, 2018 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Jun 2, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub