VDB
CVE-2019-15789
CVE-2019-15789
PUBLISHED
CVSS 8.800000190734863 HIGH
Privilege escalation vulnerability in MicroK8s allows a low privilege user with local access to obtain root access to the host by provisioning a privileged container. Fixed in MicroK8s 1.15.3.
EPSS 0.50% · 42.0th percentile
Risk Scores
CVSS 3.1
8.800000190734863
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
EPSS Score
0.50%
42.0th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| canonical | microk8s | 0 |
| Canonical | MicroK8s | 1.15 |
Timeline
- Apr 8, 2020 CVE Published
- Apr 14, 2021 EPSS Score
- Jun 23, 2021 EPSS Score
- Aug 25, 2021 EPSS Score
- Oct 27, 2021 EPSS Score
- Jan 6, 2022 EPSS Score
- Feb 4, 2022 EPSS Score
- Mar 1, 2022 EPSS Score
- Apr 1, 2022 EPSS Score
- May 3, 2022 EPSS Score
- Jul 5, 2022 EPSS Score
- Sep 7, 2022 EPSS Score
References
- https://people.canonical.com/~ubuntu-security/cve/2019/CVE-2019-15789.html url
- https://github.com/ubuntu/microk8s/pull/590 advisory
- https://pulsesecurity.co.nz/advisories/microk8s-privilege-escalation exploit
- https://nvd.nist.gov/vuln/detail/CVE-2019-15789 advisory
- https://discuss.kubernetes.io/t/explicit-use-of-sudo-in-microk8s-cli/7605 url