QID 377864
Date Published: 2023-01-03
QID 377864: Kubernetes Kubectl Potential Directory Traversal Vulnerability
Kubernetes is an open-source container-orchestration system for automating deployment, scaling, and management of containerized applications.
Affected version:
Kubernetes 1.0.x-1.12.x
Kubernetes 1.13.0-1.13.8
Kubernetes 1.14.0-1.14.4
Kubernetes 1.15.0-1.15.1
QID Detection Logic:(Authenticated)
The QID uses 'kubectl --version' command to check for vulnerable versions of Kubernetes
Successful exploitation of the vulnerability may allow an attacker to potentially create or overwrite files outside of the destination directory of the kubectl cp operation.
Solution
For more information please visit 80984
Vendor References
CVEs related to QID 377864
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| 80984 |
|