CVE-2017-1002101
In Kubernetes versions 1.3.x, 1.4.x, 1.5.x, 1.6.x and prior to versions 1.7.14, 1.8.9 and 1.9.4 containers using subpath volume mounts with any volume type (including non-privileged pods, subject to file permissions) can access files/directories outside of the volume, including the host's filesystem.
- Affected products
- Kubernetes, Suse
- Kubernetes
- β€ 1.3.10, 1.4.12, 1.5.8, 1.6.13, 1.7.14, 1.8.9, 1.9.4
- Fix
- Available
- CVSS 3.0
- 9.6 CRITICAL
- EPSS
- 11.3% (96th percentile)
- Weakness
- CWE-59
- NVD status
- Modified
- Published
- 2018-03-13
CVE-2017-1002101 at NVD
2 known exploits for CVE-2017-1002101
Proof-of-concept code and exploit modules indexed by Sploitus