← back
CVE-2018-1002100medium

CVE-2018-1002100

13Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 4.2epss 1.6%
exploitation probability
1.6%top 27% of all CVEs
observed exploitation
nono source reports it
In Kubernetes versions 1.5.x, 1.6.x, 1.7.x, 1.8.x, and prior to version 1.9.6, the kubectl cp command insecurely handles tar data returned from the container, and can be caused to overwrite arbitrary local files.
CVSS:3.0/AV:N/AC:H/PR:H/UI:R/S:U/C:N/I:H/A:N
Affected products
Kubernetes · Kubernetes