Kubernetes CRI-O CVE-2018-1000400 Remote Privilege Escalation Vulnerability
BID:104262
CVE-2018-1000400 |Info
Kubernetes CRI-O CVE-2018-1000400 Remote Privilege Escalation Vulnerability
| Bugtraq ID: | 104262 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2018-1000400 |
| Remote: | Yes |
| Local: | No |
| Published: | May 18 2018 12:00AM |
| Updated: | May 18 2018 12:00AM |
| Credit: | The vendor reported this issue. |
| Vulnerable: |
Kubernetes CRI-O 1.8 Kubernetes CRI-O 1.0.0-RC3 Kubernetes CRI-O 1.0.0 |
| Not Vulnerable: |
Kubernetes CRI-O 1.9 |
Discussion
Kubernetes CRI-O CVE-2018-1000400 Remote Privilege Escalation Vulnerability
Kubernetes CRI-O is prone to a remote privilege-escalation vulnerability.
An attacker can exploit this issue to gain elevated privileges and perform unauthorized actions.
Versions prior to CRI-O 1.9 are vulnerable.
Kubernetes CRI-O is prone to a remote privilege-escalation vulnerability.
An attacker can exploit this issue to gain elevated privileges and perform unauthorized actions.
Versions prior to CRI-O 1.9 are vulnerable.
Solution / Fix
Kubernetes CRI-O CVE-2018-1000400 Remote Privilege Escalation Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Kubernetes CRI-O CVE-2018-1000400 Remote Privilege Escalation Vulnerability
References:
References:
- [1.9] Remove ambient capabilities #1558 (Kubernetes)
- Kubernetes Homepage (kubernetes)