Lucene search

K
ibmIBM3D7E22EE099BD344BA3805E09C3D8DC042FA6C7098C653EA2911D6C2DDBD485E
HistoryDec 24, 2019 - 4:32 p.m.

Security Bulletin: A Security Vulnerability affects IBM Cloud Private - kubectl (CVE-2019-11251)

2019-12-2416:32:57
www.ibm.com
9

EPSS

0.001

Percentile

19.4%

Summary

A Security Vulnerability affects IBM Cloud Private - kubectl

Vulnerability Details

CVEID:CVE-2019-11251
**DESCRIPTION:**Kubernetes could allow a remote attacker to gain unauthorized access to the system, caused by an error in `kubectl cp` that allows a combination of two symlinks to copy a file outside of its destination directory. An attacker could exploit this vulnerability to write arbitrary files outside of the destination tree.
CVSS Base score: 5.9
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/168617 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N)

Affected Products and Versions

Affected Product(s) Version(s)
IBM Cloud Private 3.2.1 CD
IBM Cloud Private 3.2.0 CD

Remediation/Fixes

Product defect fixes and security updates are only available for the two most recent Continuous Delivery (CD) update packages

  • IBM Cloud Private 3.2.0
  • IBM Cloud Private 3.2.1

For IBM Cloud Private 3.2.0, apply November fix pack:

For IBM Cloud Private 3.2.1, apply November fix pack:

For IBM Cloud Private 3.1.0, 3.1.1, 3.1.2:

  • Upgrade to the latest Continuous Delivery (CD) update package, IBM Cloud Private 3.2.1.
  • If required, individual product fixes can be made available between CD update packages for resolution of problems. Contact IBM support for assistance

Workarounds and Mitigations

None

EPSS

0.001

Percentile

19.4%

Related for 3D7E22EE099BD344BA3805E09C3D8DC042FA6C7098C653EA2911D6C2DDBD485E