The Kubernetes kubectl cp command in versions 1.1-1.12, and versions prior to 1.13.11, 1.14.7, and 1.15.4 allows a combination of two symlinks provided by tar output of a malicious container to place a file outside of the destination directory specified in the kubectl cp invocation. This could be used to allow an attacker to place a nefarious file using a symlink, outside of the destination tree.
CVSS Details
- CVSS 3.1 Base Score: 4.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Kubernetes | — | Upgrade Kubernetes to version 1.13.11Upgrade Kubernetes to version 1.15.4Upgrade Kubernetes to version 1.14.7 | Feb 14, 2020 | Feb 3, 2020 |
| Oracle_linux | — | Upgrade kubeadmUpgrade kubectlUpgrade kubeletUpgrade kubeadm-upgradeUpgrade kubernetesUpgrade kubeadm-ha-setup | Oct 10, 2019 | Oct 9, 2019 |
| Redhat Openshift | — | Upgrade atomic-openshiftUpgrade openshift | Oct 31, 2019 | Sep 18, 2019 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Feb 3, 2020 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub