CVE-2018-1002102
05.12.2019, 16:15
Improper validation of URL redirection in the Kubernetes API server in versions prior to v1.14.0 allows an attacker-controlled Kubelet to redirect API server requests from streaming endpoints to arbitrary hosts. Impacted API servers will follow the redirect as a GET request with client-certificate credentials for authenticating to the Kubelet.
Vendor | Product | Version |
---|---|---|
kubernetes | kubernetes | 1.10.0 ≤ 𝑥 ≤ 1.13.13 |
kubernetes | kubernetes | 1.14.0:alpha0 |
kubernetes | kubernetes | 1.14.0:alpha1 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Common Weakness Enumeration
References