High severity7.1NVD Advisory· Published Mar 13, 2018· Updated Jun 17, 2026
CVE-2017-1002102
CVE-2017-1002102
Description
In Kubernetes versions 1.3.x, 1.4.x, 1.5.x, 1.6.x and prior to versions 1.7.14, 1.8.9 and 1.9.4 containers using a secret, configMap, projected or downwardAPI volume can trigger deletion of arbitrary files/directories from the nodes where they are running.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
k8s.io/kubernetesGo | >= 1.3.0, < 1.7.14 | 1.7.14 |
k8s.io/kubernetesGo | >= 1.8.0, < 1.8.9 | 1.8.9 |
k8s.io/kubernetesGo | >= 1.9.0, < 1.9.4 | 1.9.4 |
Affected products
3- ghsa-coords2 versions
>= 1.3.0, < 1.7.14+ 1 more
- (no CPE)range: >= 1.3.0, < 1.7.14
- (no CPE)range: < 0.0.20250807T150727-1.1
- Range: v1.3.x
Patches
Vulnerability mechanics
References
4- access.redhat.com/errata/RHSA-2018:0475nvdThird Party AdvisoryWEB
- github.com/advisories/GHSA-mm7g-f2gg-cw8gghsaADVISORY
- github.com/kubernetes/kubernetes/issues/60814nvdIssue TrackingVendor AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2017-1002102ghsaADVISORY
News mentions
0No linked articles in our index yet.