cbcvebase.
CVE-2019-11244
published 2019-04-22

CVE-2019-11244: In Kubernetes v1.8.x-v1.14.x, schema info is cached by kubectl in the location specified by --cache-dir (defaulting to $HOME/.kube/http-cache), written with…

PriorityP418medium5CVSS 3.1
AVLACLPRLUIRSUCNIHAN
EPSS
0.48%
38.5th percentile
In Kubernetes v1.8.x-v1.14.x, schema info is cached by kubectl in the location specified by --cache-dir (defaulting to $HOME/.kube/http-cache), written with world-writeable permissions (rw-rw-rw-). If --cache-dir is specified and pointed at a different location accessible to other users/groups, the written files may be modified by other users/groups and disrupt the kubectl invocation.

Affected

12 ranges
VendorProductVersion rangeFixed in
debiankubernetes
k8s.ioclient-go>= 1.8.0 < 1.12.91.12.9
kuberneteskubernetes1.8.0 – 1.14.1
kuberneteskubernetes>= v1.10.0 < v1.10*v1.10*
kuberneteskubernetes>= v1.11.0 < v1.11*v1.11*
kuberneteskubernetes>= v1.12.0 < v1.12*v1.12*
kuberneteskubernetes>= v1.13.0 < v1.13*v1.13*
kuberneteskubernetes>= v1.14.0 < v1.14*v1.14*
kuberneteskubernetes>= v1.8.0 < v1.8*v1.8*
kuberneteskubernetes>= v1.9.0 < v1.9*v1.9*
redhatopenshift_container_platform
redhatopenshift_container_platform

CVSS provenance

nvdv3.15.0MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:N
nvdv3.03.3LOWCVSS:3.0/AV:L/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:N
nvdv2.01.9LOWAV:L/AC:M/Au:N/C:N/I:P/A:N
vendor_debian5.0LOW
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.