CVE-2019-1002101
Summary
| CVE | CVE-2019-1002101 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-04-01 14:29:00 UTC |
| Updated | 2023-11-07 03:02:00 UTC |
| Description | The kubectl cp command allows copying files between containers and the user machine. To copy files from a container, Kubernetes creates a tar inside the container, copies it over the network, and kubectl unpacks it on the user’s machine. If the tar binary in the container is malicious, it could run any code and output unexpected, malicious results. An attacker could use this to write files to any path on the user’s machine when kubectl cp is called, limited only by the system permissions of the local user. The untar function can both create and follow symbolic links. The issue is resolved in kubectl v1.11.9, v1.12.7, v1.13.5, and v1.14.0. |
Risk And Classification
Problem Types: CWE-59
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Kubernetes | Kubernetes | All | All | All | All |
| Application | Kubernetes | Kubernetes | 1.14.0 | All | All | All |
| Application | Kubernetes | Kubernetes | All | All | All | All |
| Application | Kubernetes | Kubernetes | 1.14.0 | All | All | All |
| Application | Redhat | Openshift Container Platform | 3.10 | All | All | All |
| Application | Redhat | Openshift Container Platform | 3.11 | All | All | All |
| Application | Redhat | Openshift Container Platform | 3.9 | All | All | All |
| Application | Redhat | Openshift Container Platform | 3.10 | All | All | All |
| Application | Redhat | Openshift Container Platform | 3.11 | All | All | All |
| Application | Redhat | Openshift Container Platform | 3.9 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| [SECURITY] Fedora 30 Update: kubernetes-1.13.5-1.fc30 - package-announce - Fedora Mailing-Lists | FEDORA | lists.fedoraproject.org | |
| Comprehensive Cloud Security | Prisma - Palo Alto Networks | MISC | www.twistlock.com | |
| Red Hat Customer Portal | REDHAT | access.redhat.com | |
| oss-security - [ANNOUNCE] Incomplete fixes for CVE-2019-1002101, kubectl cp potential directory traversal - CVE-2019-11246 | MLIST | www.openwall.com | |
| CVE-2019-1002101 - Red Hat Customer Portal | MISC | access.redhat.com | Third Party Advisory |
| [SECURITY] Fedora 30 Update: kubernetes-1.15.2-1.fc30 - package-announce - Fedora Mailing-Lists | FEDORA | lists.fedoraproject.org | |
| CVE-2019-1002101: kubectl fix potential directory traversal by soltysh · Pull Request #75037 · kubernetes/kubernetes · GitHub | MISC | github.com | Patch, Third Party Advisory |
| Red Hat Customer Portal | REDHAT | access.redhat.com | |
| [SECURITY] Fedora 30 Update: kubernetes-1.13.5-1.fc30 - package-announce - Fedora Mailing-Lists | lists.fedoraproject.org | ||
| Malformed Request | BID | www.securityfocus.com | Third Party Advisory, VDB Entry |
| [SECURITY] Fedora 30 Update: kubernetes-1.15.2-1.fc30 - package-announce - Fedora Mailing-Lists | lists.fedoraproject.org | ||
| oss-security - Kubernetes v1.13.9, v1.14.5, v1.15.2 released to address CVE-2019-11247, CVE-2019-11249 | MLIST | www.openwall.com | |
| Red Hat Customer Portal | REDHAT | access.redhat.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
LEGACY: Ariel Zelivansky of Twistlock
There are currently no legacy QID mappings associated with this CVE.