CVE-2019-11246 describes a vulnerability in the kubectl cp command, affecting Kubernetes versions prior to 1.12.9, 1.13.6, and 1.14.2, as well as several older versions. This flaw allows a malicious tar binary within a container to execute arbitrary code on the user's machine during a file copy operation, potentially writing files to any path. Rated Medium with a CVSS score of 6.5, the vulnerability requires user interaction (UI:R) and an attacker to control the container's tar binary, leading to high integrity impact (I:H) on the user's system. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or inclusion in the KEV catalog, though it has received some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 1.0.0, <= 1.12.10CPE matchmatch criteria | cpe:2.3:a:kubernetes:kubernetes:*:*:*:*:*:*:*:* | ||
>= 1.13.0, < 1.13.9CPE matchmatch criteria | cpe:2.3:a:kubernetes:kubernetes:*:*:*:*:*:*:*:* | ||
>= 1.14.0, < 1.14.5CPE matchmatch criteria | cpe:2.3:a:kubernetes:kubernetes:*:*:*:*:*:*:*:* | ||
>= 1.15.0, < 1.15.2CPE matchmatch criteria | cpe:2.3:a:kubernetes:kubernetes:*:*:*:*:*:*:*:* | ||
1.12.11CPE matchmatch criteria | cpe:2.3:a:kubernetes:kubernetes:1.12.11:beta0:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.