CVE-2017-1002100
14.09.2017, 13:29
Default access permissions for Persistent Volumes (PVs) created by the Kubernetes Azure cloud provider in versions 1.6.0 to 1.6.5 are set to "container" which exposes a URI that can be accessed without authentication on the public internet. Access to the URI string requires privileged access to the Kubernetes cluster or authenticated access to the Azure portal.Enginsight
| Vendor | Product | Version |
|---|---|---|
| kubernetes | kubernetes | 1.6.0 |
| kubernetes | kubernetes | 1.6.0:alpha.0 |
| kubernetes | kubernetes | 1.6.0:alpha.1 |
| kubernetes | kubernetes | 1.6.0:alpha.2 |
| kubernetes | kubernetes | 1.6.0:alpha.3 |
| kubernetes | kubernetes | 1.6.0:beta.0 |
| kubernetes | kubernetes | 1.6.0:beta.1 |
| kubernetes | kubernetes | 1.6.0:beta.2 |
| kubernetes | kubernetes | 1.6.0:beta.3 |
| kubernetes | kubernetes | 1.6.0:beta.4 |
| kubernetes | kubernetes | 1.6.0:rc.1 |
| kubernetes | kubernetes | 1.6.1 |
| kubernetes | kubernetes | 1.6.1:beta.0 |
| kubernetes | kubernetes | 1.6.2 |
| kubernetes | kubernetes | 1.6.2:beta.0 |
| kubernetes | kubernetes | 1.6.3 |
| kubernetes | kubernetes | 1.6.3:beta.0 |
| kubernetes | kubernetes | 1.6.3:beta.1 |
| kubernetes | kubernetes | 1.6.4 |
| kubernetes | kubernetes | 1.6.4:beta.0 |
| kubernetes | kubernetes | 1.6.4:beta.1 |
| kubernetes | kubernetes | 1.6.5 |
| kubernetes | kubernetes | 1.6.5:beta.0 |
𝑥
= Vulnerable software versions
Debian Releases
Common Weakness Enumeration