CVE-2017-1002101
13.03.2018, 17:29
In Kubernetes versions 1.3.x, 1.4.x, 1.5.x, 1.6.x and prior to versions 1.7.14, 1.8.9 and 1.9.4 containers using subpath volume mounts with any volume type (including non-privileged pods, subject to file permissions) can access files/directories outside of the volume, including the host's filesystem.
Vendor | Product | Version |
---|---|---|
kubernetes | kubernetes | 1.3.0 ≤ 𝑥 ≤ 1.3.10 |
kubernetes | kubernetes | 1.4.0 ≤ 𝑥 ≤ 1.4.12 |
kubernetes | kubernetes | 1.5.0 ≤ 𝑥 ≤ 1.5.8 |
kubernetes | kubernetes | 1.6.0 ≤ 𝑥 ≤ 1.6.13 |
kubernetes | kubernetes | 1.7.0 ≤ 𝑥 < 1.7.14 |
kubernetes | kubernetes | 1.8.0 ≤ 𝑥 < 1.8.9 |
kubernetes | kubernetes | 1.9.0 ≤ 𝑥 < 1.9.4 |
𝑥
= Vulnerable software versions

Debian Releases
References