kubectl是一款用于运行针对Kubernetes集群的命令的命令行程序。 kubectl中存在权限许可和访问控制问题漏洞。该漏洞源于网络系统或产品缺乏有效的权限许可和访问控制措施。以下产品及版本受到影响:Kubernetes 1.13.9之前版本,1.14.5之前版本,1.15.2之前版本,1.7版本,1.8版本,1.9版本,1.10版本,1.11版本,1.12版本。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Kubernetes | Kubernetes | prior to 1.13.9 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2019-11245 | kubelet-started container uid changes to root after first restart or if image is already p | |
| CVE-2019-11246 | kubectl cp allows symlink directory traversal | |
| CVE-2019-11248 | Kubernetes kubelet exposes /debug/pprof info on healthz port | |
| CVE-2019-11249 | kubectl cp allows symlink directory traversal | |
| CVE-2019-11250 | Kubernetes client-go logs authorization headers at debug verbosity levels |
No comments yet