CVE-2018-1002102
05.12.2019, 16:15
Improper validation of URL redirection in the Kubernetes API server in versions prior to v1.14.0 allows an attacker-controlled Kubelet to redirect API server requests from streaming endpoints to arbitrary hosts. Impacted API servers will follow the redirect as a GET request with client-certificate credentials for authenticating to the Kubelet.
| Vendor | Product | Version |
|---|---|---|
| kubernetes | kubernetes | 1.10.0 ≤ 𝑥 ≤ 1.13.13 |
| kubernetes | kubernetes | 1.14.0:alpha0 |
| kubernetes | kubernetes | 1.14.0:alpha1 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Common Weakness Enumeration
References