Moderate severityNVD Advisory· Published Mar 13, 2018· Updated Aug 5, 2024
CVE-2017-1002102
CVE-2017-1002102
Description
In Kubernetes versions 1.3.x, 1.4.x, 1.5.x, 1.6.x and prior to versions 1.7.14, 1.8.9 and 1.9.4 containers using a secret, configMap, projected or downwardAPI volume can trigger deletion of arbitrary files/directories from the nodes where they are running.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
k8s.io/kubernetesGo | >= 1.3.0, < 1.7.14 | 1.7.14 |
k8s.io/kubernetesGo | >= 1.8.0, < 1.8.9 | 1.8.9 |
k8s.io/kubernetesGo | >= 1.9.0, < 1.9.4 | 1.9.4 |
Affected products
1- Range: v1.3.x
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4- access.redhat.com/errata/RHSA-2018:0475ghsavendor-advisoryx_refsource_REDHATWEB
- github.com/advisories/GHSA-mm7g-f2gg-cw8gghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2017-1002102ghsaADVISORY
- github.com/kubernetes/kubernetes/issues/60814ghsax_refsource_CONFIRMWEB
News mentions
0No linked articles in our index yet.