cbcvebase.
CVE-2019-11244
published 2019-04-22

CVE-2019-11244: In Kubernetes v1.8.x-v1.14.x, schema info is cached by kubectl in the location specified by --cache-dir (defaulting to $HOME/.kube/http-cache), written with…

medium5CVSS 3.1
AVLACLPRLUIRSUCNIHAN
In Kubernetes v1.8.x-v1.14.x, schema info is cached by kubectl in the location specified by --cache-dir (defaulting to $HOME/.kube/http-cache), written with world-writeable permissions (rw-rw-rw-). If --cache-dir is specified and pointed at a different location accessible to other users/groups, the written files may be modified by other users/groups and disrupt the kubectl invocation.

Affected

12 ranges
VendorProductVersion rangeFixed in
debiankubernetes
k8s.ioclient-go>= 1.8.0 < 1.12.91.12.9
kuberneteskubernetes1.8.0 – 1.14.1
kuberneteskubernetes>= v1.10.0 < v1.10*v1.10*
kuberneteskubernetes>= v1.11.0 < v1.11*v1.11*
kuberneteskubernetes>= v1.12.0 < v1.12*v1.12*
kuberneteskubernetes>= v1.13.0 < v1.13*v1.13*
kuberneteskubernetes>= v1.14.0 < v1.14*v1.14*
kuberneteskubernetes>= v1.8.0 < v1.8*v1.8*
kuberneteskubernetes>= v1.9.0 < v1.9*v1.9*
redhatopenshift_container_platform
redhatopenshift_container_platform