Description
In Kubernetes versions 1.3.x, 1.4.x, 1.5.x, 1.6.x and prior to versions 1.7.14, 1.8.9 and 1.9.4 containers using a secret, configMap, projected or downwardAPI volume can trigger deletion of arbitrary files/directories from the nodes where they are running.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-4588 | In Kubernetes versions 1.3.x, 1.4.x, 1.5.x, 1.6.x and prior to versions 1.7.14, 1.8.9 and 1.9.4 containers using a secret, configMap, projected or downwardAPI volume can trigger deletion of arbitrary files/directories from the nodes where they are running. |
Github GHSA |
GHSA-mm7g-f2gg-cw8g | Kubernetes arbitrary file overwrite |
References
History
No history.
Status: PUBLISHED
Assigner: kubernetes
Published:
Updated: 2024-08-05T22:00:41.652Z
Reserved: 2017-12-07T00:00:00.000Z
Link: CVE-2017-1002102
No data.
Status : Modified
Published: 2018-03-13T17:29:00.280
Modified: 2024-11-21T03:04:58.700
Link: CVE-2017-1002102
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA