CVE-2015-5305Path Traversal in Kubernetes Kubernetes

CWE-22Path Traversal8 documents7 sources
Severity
6.4MEDIUMNVD
EPSS
0.3%
top 48.22%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 6
Latest updateFeb 15

Description

Directory traversal vulnerability in Kubernetes, as used in Red Hat OpenShift Enterprise 3.0, allows attackers to write to arbitrary files via a crafted object type name, which is not properly handled before passing it to etcd.

CVSS vector

AV:N/AC:L/C:N/I:P/A:PExploitability: 10.0 | Impact: 4.9

Affected Packages3 packages

🔴Vulnerability Details

4
OSV
Directory Traversal in Kubernetes2022-02-15
OSV
Directory traversal in k8s.io/kubernetes2022-02-15
GHSA
Directory Traversal in Kubernetes2022-02-15
CVEList
CVE-2015-5305: Directory traversal vulnerability in Kubernetes, as used in Red Hat OpenShift Enterprise 32015-11-06

📋Vendor Advisories

2
Red Hat
Kubernetes: Missing name validation allows path traversal in etcd2015-10-27
Debian
CVE-2015-5305: kubernetes - Directory traversal vulnerability in Kubernetes, as used in Red Hat OpenShift En...2015

💬Community

1
Bugzilla
CVE-2015-5305 Kubernetes: Missing name validation allows path traversal in etcd2015-10-21
CVE-2015-5305 — Path Traversal in Kubernetes Kubernetes | cvebase