VDB

DEBIAN-CVE-2018-1002100

DEBIAN-CVE-2018-1002100 PUBLISHED CVSS 5.5 MEDIUM

In Kubernetes versions 1.5.x, 1.6.x, 1.7.x, 1.8.x, and prior to version 1.9.6, the kubectl cp command insecurely handles tar data returned from the container, and can be caused to overwrite arbitrary local files.

Risk Scores

CVSS v3.0
5.5
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

Affected Products

VendorProductVersions
Debian:14kubernetes0, 0, 0
Debian:13kubernetes0, 0, 0
Debian:12kubernetes0, 0, 0
Debian:11kubernetes0, 0, 0

Timeline

  • Jun 2, 2018 CVE Published
  • Apr 28, 2026 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›