CVE-2018-1002100 Vulnerability Details
/
/
/
CVE-2018-1002100 Metadata Quick Info
CVE Published: 01/06/2018 |
CVE Updated: 16/09/2024 |
CVE Year: 2018
Source: kubernetes |
Vendor: Kubernetes |
Product: Kubernetes
Status : PUBLISHED
CVE-2018-1002100 Description
In Kubernetes versions 1.5.x, 1.6.x, 1.7.x, 1.8.x, and prior to version 1.9.6, the kubectl cp command insecurely handles tar data returned from the container, and can be caused to overwrite arbitrary local files.
Metrics
CVSS Version: 3.1 |
Base Score: n/a
Vector: n/a
l➤ Exploitability Metrics:
Attack Vector (AV)*
Attack Complexity (AC)*
Privileges Required (PR)*
User Interaction (UI)*
Scope (S)*
l➤ Impact Metrics:
Confidentiality Impact (C)*
Integrity Impact (I)*
Availability Impact (A)*
Weakness Enumeration (CWE)
CWE-ID:
CWE Name: directory traversal vulnerability
Source: Kubernetes
Common Attack Pattern Enumeration and Classification (CAPEC)
CAPEC-ID:
CAPEC Description:
Source: NVD (National Vulnerability Database).