cbcvebase.
CVE-2018-1002101
published 2018-12-05

CVE-2018-1002101: In Kubernetes versions 1.9.0-1.9.9, 1.10.0-1.10.5, and 1.11.0-1.11.1, user input was handled insecurely while setting up volume mounts on Windows nodes, which…

PriorityP353critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EPSS
4.11%
89.5th percentile
In Kubernetes versions 1.9.0-1.9.9, 1.10.0-1.10.5, and 1.11.0-1.11.1, user input was handled insecurely while setting up volume mounts on Windows nodes, which could lead to command line argument injection.

Affected

10 ranges
VendorProductVersion rangeFixed in
debiankubernetes
k8s.iokubernetes>= 1.10.0 < 1.10.61.10.6
k8s.iokubernetes>= 1.11.0 < 1.11.21.11.2
k8s.iokubernetes>= 1.9.0 < 1.9.101.9.10
kuberneteskubernetes1.10.0 – 1.10.5
kuberneteskubernetes1.11.0 – 1.11.1
kuberneteskubernetes1.9.0 – 1.9.9
kuberneteskubernetes>= unspecified < v1.9.10v1.9.10
kuberneteskubernetes>= unspecified < v1.10.6v1.10.6
kuberneteskubernetes>= unspecified < v1.11.2v1.11.2

CVSS provenance

nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
vendor_debian5.9LOW
vendor_redhat5.9MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.