Lucene search

K
githubGitHub Advisory DatabaseGHSA-MM7G-F2GG-CW8G
HistoryMay 13, 2022 - 1:38 a.m.

Kubernetes arbitrary file overwrite

2022-05-1301:38:23
CWE-284
GitHub Advisory Database
github.com
9
kubernetes
container
security
vulnerability
versions 1.3.x-1.6.x
1.7.14
1.8.9
1.9.4

CVSS2

6.3

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:M/Au:N/C:N/I:C/A:C

CVSS3

7.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

LOW

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H

EPSS

0

Percentile

12.6%

In Kubernetes versions 1.3.x, 1.4.x, 1.5.x, 1.6.x and prior to versions 1.7.14, 1.8.9 and 1.9.4 containers using a secret, configMap, projected or downwardAPI volume can trigger deletion of arbitrary files/directories from the nodes where they are running.

Affected configurations

Vulners
Node
k8s.iokubernetesRange1.3.01.7.13
OR
k8s.iokubernetesRange1.9.01.9.3
OR
k8s.iokubernetesRange1.8.01.8.8
VendorProductVersionCPE
k8s.iokubernetes*cpe:2.3:a:k8s.io:kubernetes:*:*:*:*:*:*:*:*

CVSS2

6.3

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:M/Au:N/C:N/I:C/A:C

CVSS3

7.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

LOW

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H

EPSS

0

Percentile

12.6%