Unrated severityNVD Advisory· Published Dec 5, 2019· Updated Sep 17, 2024
Kubernetes API server follows unvalidated redirects from streaming Kubelet endpoints
CVE-2018-1002102
Description
Improper validation of URL redirection in the Kubernetes API server in versions prior to v1.14.0 allows an attacker-controlled Kubelet to redirect API server requests from streaming endpoints to arbitrary hosts. Impacted API servers will follow the redirect as a GET request with client-certificate credentials for authenticating to the Kubelet.
Affected products
1- Range: v1.14
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Q56CULSH7F7BC4NPS67ZS23ZCLL5TIVK/mitrevendor-advisoryx_refsource_FEDORA
- github.com/kubernetes/kubernetes/issues/85867mitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.