Critical severity9.8NVD Advisory· Published Dec 5, 2018· Updated Jun 17, 2026
CVE-2018-1002105
CVE-2018-1002105
Description
In all Kubernetes versions prior to v1.10.11, v1.11.5, and v1.12.3, incorrect handling of error responses to proxied upgrade requests in the kube-apiserver allowed specially crafted requests to establish a connection through the Kubernetes API server to backend servers, then send arbitrary requests over the same connection directly to the backend, authenticated with the Kubernetes API server's TLS credentials used to establish the backend connection.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
github.com/kubernetes/kubernetesGo | < 1.10.11 | 1.10.11 |
github.com/kubernetes/kubernetesGo | >= 1.11.0, < 1.11.5 | 1.11.5 |
github.com/kubernetes/kubernetesGo | >= 1.12.0, < 1.12.3 | 1.12.3 |
Affected products
41cpe:2.3:a:kubernetes:kubernetes:*:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:kubernetes:kubernetes:*:*:*:*:*:*:*:*range: >=1.0.0,<=1.9.11
- cpe:2.3:a:kubernetes:kubernetes:1.9.12:beta0:*:*:*:*:*:*
- (no CPE)range: v1.0.x
cpe:2.3:a:redhat:openshift_container_platform:3.10:*:*:*:*:*:*:*+ 7 more
- cpe:2.3:a:redhat:openshift_container_platform:3.10:*:*:*:*:*:*:*
- cpe:2.3:a:redhat:openshift_container_platform:3.11:*:*:*:*:*:*:*
- cpe:2.3:a:redhat:openshift_container_platform:3.2:*:*:*:*:*:*:*
- cpe:2.3:a:redhat:openshift_container_platform:3.3:*:*:*:*:*:*:*
- cpe:2.3:a:redhat:openshift_container_platform:3.4:*:*:*:*:*:*:*
- cpe:2.3:a:redhat:openshift_container_platform:3.5:*:*:*:*:*:*:*
- cpe:2.3:a:redhat:openshift_container_platform:3.6:*:*:*:*:*:*:*
- cpe:2.3:a:redhat:openshift_container_platform:3.8:*:*:*:*:*:*:*
- osv-coords29 versionspkg:apk/chainguard/kubeflow-pipelinespkg:apk/chainguard/kubeflow-pipelines-apiserverpkg:apk/chainguard/kubeflow-pipelines-cache-deployerpkg:apk/chainguard/kubeflow-pipelines-cache-deployer-compatpkg:apk/chainguard/kubeflow-pipelines-cache_serverpkg:apk/chainguard/kubeflow-pipelines-frontendpkg:apk/chainguard/kubeflow-pipelines-metadata-envoy-configpkg:apk/chainguard/kubeflow-pipelines-metadata-writerpkg:apk/chainguard/kubeflow-pipelines-metadata-writer-compatpkg:apk/chainguard/kubeflow-pipelines-persistence_agentpkg:apk/chainguard/kubeflow-pipelines-scheduledworkflowpkg:apk/chainguard/kubeflow-pipelines-viewer-crd-controllerpkg:apk/wolfi/kubeflow-pipelinespkg:apk/wolfi/kubeflow-pipelines-apiserverpkg:apk/wolfi/kubeflow-pipelines-cache-deployerpkg:apk/wolfi/kubeflow-pipelines-cache-deployer-compatpkg:apk/wolfi/kubeflow-pipelines-cache_serverpkg:apk/wolfi/kubeflow-pipelines-frontendpkg:apk/wolfi/kubeflow-pipelines-metadata-envoy-configpkg:apk/wolfi/kubeflow-pipelines-metadata-writerpkg:apk/wolfi/kubeflow-pipelines-metadata-writer-compatpkg:apk/wolfi/kubeflow-pipelines-persistence_agentpkg:apk/wolfi/kubeflow-pipelines-scheduledworkflowpkg:apk/wolfi/kubeflow-pipelines-viewer-crd-controllerpkg:golang/github.com/kubernetes/kubernetespkg:rpm/opensuse/cri-o&distro=openSUSE%20Leap%2015.1pkg:rpm/opensuse/cri-tools&distro=openSUSE%20Leap%2015.1pkg:rpm/opensuse/go1.14&distro=openSUSE%20Leap%2015.1pkg:rpm/opensuse/kubernetes&distro=openSUSE%20Leap%2015.1
< 0+ 28 more
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 1.10.11
- (no CPE)range: < 1.17.1-lp151.2.2
- (no CPE)range: < 1.18.0-lp151.2.1
- (no CPE)range: < 1.14-lp151.6.1
- (no CPE)range: < 1.18.0-lp151.5.1
Patches
Vulnerability mechanics
References
31- github.com/kubernetes/kubernetes/issues/71411nvdIssue TrackingMitigationPatchThird Party AdvisoryWEB
- www.exploit-db.com/exploits/46052/nvdExploitThird Party AdvisoryVDB Entry
- www.exploit-db.com/exploits/46053/nvdExploitThird Party AdvisoryVDB Entry
- www.securityfocus.com/bid/106068nvdThird Party AdvisoryVDB Entry
- access.redhat.com/errata/RHSA-2018:3537nvdThird Party AdvisoryWEB
- access.redhat.com/errata/RHSA-2018:3549nvdThird Party AdvisoryWEB
- access.redhat.com/errata/RHSA-2018:3551nvdThird Party AdvisoryWEB
- access.redhat.com/errata/RHSA-2018:3598nvdThird Party AdvisoryWEB
- access.redhat.com/errata/RHSA-2018:3624nvdThird Party AdvisoryWEB
- access.redhat.com/errata/RHSA-2018:3742nvdThird Party AdvisoryWEB
- access.redhat.com/errata/RHSA-2018:3752nvdThird Party AdvisoryWEB
- access.redhat.com/errata/RHSA-2018:3754nvdThird Party AdvisoryWEB
- github.com/advisories/GHSA-579h-mv94-g4gpghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2018-1002105ghsaADVISORY
- security.netapp.com/advisory/ntap-20190416-0001/nvdThird Party Advisory
- www.coalfire.com/The-Coalfire-Blog/December-2018/Kubernetes-Vulnerability-What-You-Can-Should-DonvdMitigationThird Party AdvisoryWEB
- github.com/kubernetes/kubernetes/commit/2257c1ecbe3c0cf71dd50b82752ae189c94ec905ghsaWEB
- groups.google.com/forum/ghsaWEB
- lists.opensuse.org/opensuse-security-announce/2020-04/msg00041.htmlghsaWEB
- security.netapp.com/advisory/ntap-20190416-0001ghsaWEB
- www.exploit-db.com/exploits/46052ghsaWEB
- www.exploit-db.com/exploits/46053ghsaWEB
- www.openwall.com/lists/oss-security/2019/06/28/2ghsaWEB
- www.openwall.com/lists/oss-security/2019/07/06/3ghsaWEB
- www.openwall.com/lists/oss-security/2019/07/06/4ghsaWEB
- www.securityfocus.com/bid/106068ghsaWEB
- lists.opensuse.org/opensuse-security-announce/2020-04/msg00041.htmlnvd
- www.openwall.com/lists/oss-security/2019/06/28/2nvd
- www.openwall.com/lists/oss-security/2019/07/06/3nvd
- www.openwall.com/lists/oss-security/2019/07/06/4nvd
- groups.google.com/forum/nvd
News mentions
0No linked articles in our index yet.