CVE-2018-1002102 is a low-severity vulnerability affecting Kubernetes API servers prior to version 1.14.0, including those in Fedora. It allows a compromised Kubelet to redirect API server streaming requests to arbitrary external hosts, potentially exposing client-certificate credentials. The attack requires high privileges and user interaction, with a low impact on confidentiality and no impact on integrity or availability. There is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 1.10.0, <= 1.13.13CPE matchmatch criteria | cpe:2.3:a:kubernetes:kubernetes:*:*:*:*:*:*:*:* | ||
1.14.0CPE matchmatch criteria | cpe:2.3:a:kubernetes:kubernetes:1.14.0:alpha0:*:*:*:*:*:* | ||
1.14.0CPE matchmatch criteria | cpe:2.3:a:kubernetes:kubernetes:1.14.0:alpha1:*:*:*:*:*:* | ||
31CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:31:*:*:*:*:*:*:* | ||
>= v1.14, < v1.14.0CPE match | cpe:2.3:a:kubernetes:kubernetes:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:C/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.0 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
kubernetes: improper validation of URL redirection in the Kubernetes API server allows an attacker-controlled Kubelet to redirect API server requests from streaming endpoints
Dec 3, 2019Unvalidated redirect
Unvalidated redirect
Unvalidated redirect
Unvalidated redirect