CVE-2019-11244

CVSS v3.1 5 (Medium)
50% Progress
CVSS v2.0 1.9 (Low)
19% Progress
EPSS 0.08 % (34th)
0.08% Progress
Affected Products 3
Advisories 3

In Kubernetes v1.8.x-v1.14.x, schema info is cached by kubectl in the location specified by --cache-dir (defaulting to $HOME/.kube/http-cache), written with world-writeable permissions (rw-rw-rw-). If --cache-dir is specified and pointed at a different location accessible to other users/groups, the written files may be modified by other users/groups and disrupt the kubectl invocation.

Weaknesses
CWE-524
Use of Cache Containing Sensitive Information
CWE-732
Incorrect Permission Assignment for Critical Resource
CVE Status
PUBLISHED
CNA
Kubernetes
Published Date
2019-04-22 15:29:00
(5 years ago)
Updated Date
2020-10-02 13:18:57
(4 years ago)

Affected Products

Loading...
Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Kubernetes from 1.8.0 version and 1.14.1 and prior versions cpe:2.3:a:kubernetes:kubernetes >= 1.8.0 <= 1.14.1

Configuration #2

    CPE23 From Up To
  Netapp Trident cpe:2.3:a:netapp:trident:-

Configuration #3

    CPE23 From Up To
  Redhat Openshift Container Platform 3.11 cpe:2.3:a:redhat:openshift_container_platform:3.11
  Redhat Openshift Container Platform 4.1 cpe:2.3:a:redhat:openshift_container_platform:4.1
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...