在 Kubernetes 的 客户端中,Windows 平台上的 命令存在一个路径遍历漏洞。当从容器中复制文件时, 会在容器内部执行 命令以构建 tar 归档文件,通过网络将其传输到本地机器,并在本地解包。如果容器内的 二进制文件是恶意的,攻击者可能执行任意代码并产生非预期的输出,从而在调用 时,将文件写入本地用户机器上的任意路径(受限于本地用户的系统权限)。该问题仅影响运行在 Windows 系统上的 客户端。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Kubernetes | Kubernetes | v1.36.0 ~ v1.36.4 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet