CVE-2019-11245 affects Kubernetes kubelet versions v1.13.6 and v1.14.2, allowing containers without an explicit runAsUser to run as root (uid 0) upon restart or if the image was previously pulled. This vulnerability has a CVSS score of 7.8 (High), indicating a local attack vector with low complexity, leading to high confidentiality, integrity, and availability impacts. While there is no known active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), the vulnerability has garnered some community discussion and media coverage, suggesting awareness among security professionals.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.13.6CPE matchmatch criteria | cpe:2.3:a:kubernetes:kubernetes:1.13.6:*:*:*:*:*:*:* | ||
1.14.2CPE matchmatch criteria | cpe:2.3:a:kubernetes:kubernetes:1.14.2:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Kubelet Incorrect Privilege Assignment
Apr 24, 2024kubernetes: container uid changes to root after first restart
May 24, 2019container uid changes to root after first restart or if image is already pulled to the node
container uid changes to root after first restart or if image is already pulled to the node
container uid changes to root after first restart or if image is already pulled to the node
container uid changes to root after first restart or if image is already pulled to the node