Medium severity4.8NVD Advisory· Published Feb 3, 2020· Updated Jun 17, 2026
CVE-2019-11251
CVE-2019-11251
Description
The Kubernetes kubectl cp command in versions 1.1-1.12, and versions prior to 1.13.11, 1.14.7, and 1.15.4 allows a combination of two symlinks provided by tar output of a malicious container to place a file outside of the destination directory specified in the kubectl cp invocation. This could be used to allow an attacker to place a nefarious file using a symlink, outside of the destination tree.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
k8s.io/kubernetesGo | >= 1.13.10, < 1.13.11 | 1.13.11 |
k8s.io/kubernetesGo | >= 1.14.6, < 1.14.7 | 1.14.7 |
k8s.io/kubernetesGo | >= 1.15.3, < 1.16.0 | 1.16.0 |
Affected products
5prior to 1.13.11+ 2 more
- (no CPE)range: prior to 1.13.11
- cpe:2.3:a:kubernetes:kubernetes:*:*:*:*:*:*:*:*range: >=1.13.0,<1.13.11
- cpe:2.3:a:kubernetes:kubernetes:1.1-1.12:*:*:*:*:*:*:*
- ghsa-coords2 versions
>= 1.13.10, < 1.13.11+ 1 more
- (no CPE)range: >= 1.13.10, < 1.13.11
- (no CPE)range: < 0.0.20250807T150727-1.1
Patches
Vulnerability mechanics
References
5- github.com/advisories/GHSA-6qfg-8799-r575ghsaADVISORY
- github.com/kubernetes/kubernetes/issues/87773nvdThird Party AdvisoryWEB
- groups.google.com/d/msg/kubernetes-announce/YYtEFdFimZ4/nZnOezZuBgAJnvdMailing ListThird Party AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2019-11251ghsaADVISORY
- github.com/kubernetes/kubernetes/pull/82143ghsaWEB
News mentions
0No linked articles in our index yet.