QID 377853

Date Published: 2023-01-04

QID 377853: Kubernetes Kublet Node Disk Denial of Service (DoS) Vulnerability

Kubernetes is an open-source container-orchestration system for automating deployment, scaling, and management of containerized applications.

Affected version:
kubelet v1.18.0-1.18.5
kubelet v1.17.0-1.17.8
kubelet prior to v1.16.13
QID Detection Logic:(Authenticated)
The QID uses 'kubectl version' command to check for vulnerable versions of Kubernetes

Successful exploitation of the vulnerability may allow an attacker to read docker config files

  • CVSS V3 rated as Medium - 5.5 severity.
  • CVSS V2 rated as Low - 2.1 severity.
  • Solution
    For more information please visit 93032

    CVEs related to QID 377853

    Software Advisories
    Advisory ID Software Component Link
    93032 URL Logo github.com/kubernetes/kubernetes/issues/93032