Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2018-1002102

15
FAUCET Score

CVE-2018-1002102 is a low-severity vulnerability affecting Kubernetes API servers prior to version 1.14.0, including those in Fedora. It allows a compromised Kubelet to redirect API server streaming requests to arbitrary external hosts, potentially exposing client-certificate credentials. The attack requires high privileges and user interaction, with a low impact on confidentiality and no impact on integrity or availability. There is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.

Impacted Technologies

VendorProductVersion(s)CPE
>= 1.10.0, <= 1.13.13CPE matchmatch criteria
cpe:2.3:a:kubernetes:kubernetes:*:*:*:*:*:*:*:*
1.14.0CPE matchmatch criteria
cpe:2.3:a:kubernetes:kubernetes:1.14.0:alpha0:*:*:*:*:*:*
1.14.0CPE matchmatch criteria
cpe:2.3:a:kubernetes:kubernetes:1.14.0:alpha1:*:*:*:*:*:*
31CPE matchmatch criteria
cpe:2.3:o:fedoraproject:fedora:31:*:*:*:*:*:*:*
>= v1.14, < v1.14.0CPE match
cpe:2.3:a:kubernetes:kubernetes:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

2.6LOW

CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:C/C:L/I:N/A:N

Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
HIGH
User Interaction
REQUIRED
Scope
CHANGED
Confidentiality Impact
LOW
Integrity Impact
NONE
Availability Impact
NONE
Exploitability Score
1.0
Impact Score
1.4
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.62%
Probability of exploitation in next 30 days
EPSS Percentile
46.0%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0062 is in the 83rd percentile among its peer group of 43 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.0 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (6)

check_pointpatch availablevia llm_extracted
View patch
chromepatch availablevia llm_extracted
View patch
infiniflowpatch availablevia llm_extracted
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 3.11Fixed in: atomic-openshift-0:3.11.346-1.git.0.ea10721.el7
View patch
vuepatch availablevia llm_extracted
View patch
github_advisoryworkaround availablevia nvd_reference
View patch

Vendor Advisories (5)

redhatCVE-2018-1002102Low

kubernetes: improper validation of URL redirection in the Kubernetes API server allows an attacker-controlled Kubelet to redirect API server requests from streaming endpoints

Dec 3, 2019
vuellm-vue-eef6b7fa8fb9534f

Unvalidated redirect

chromellm-chrome-b9446694b8062994

Unvalidated redirect

check_pointllm-check_point-608090078d57afea

Unvalidated redirect

infiniflowllm-infiniflow-2b44242112eedc76

Unvalidated redirect

References

github.com / kubernetes/kubernetes/issues/85867
Issue TrackingMitigationThird Party Advisory
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/Q56CULSH7F7BC4NPS67ZS23ZCLL5TIVK