CVE-2018-1002105
75Vexday Risk Score
Keep watching. It has a public proof of concept.
ssvc Attendcvss 9.8epss 87%
from disclosure to weapon0 days
Published on NVDDec 5
1st PoCDec 5
exploitation probability
87%top 1% of all CVEs
observed exploitation
nono source reports it
9 public exploit(s)
In all Kubernetes versions prior to v1.10.11, v1.11.5, and v1.12.3, incorrect handling of error responses to proxied upgrade requests in the kube-apiserver allowed specially crafted requests to establish a connection through the Kubernetes API server to backend servers, then send arbitrary requests over the same connection directly to the backend, authenticated with the Kubernetes API server's TLS credentials used to establish the backend connection.
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
Kubernetes · Kubernetespublic PoCs found — 9
exploitdbwww.exploit-db.com/exploits/46053unverifiedexploitdbwww.exploit-db.com/exploits/46052unverifiedgithubgithub.com/evict/poc_CVE-2018-1002105★ 222githubgithub.com/gravitational/cve-2018-1002105★ 191githubgithub.com/imlzw/Kubernetes-1.12.3-all-auto-install★ 4githubgithub.com/bgeesaman/cve-2018-1002105★ 1githubgithub.com/sh-ubh/CVE-2018-1002105★ 1cve_referencewww.exploit-db.com/exploits/46052/unverifiedcve_referencewww.exploit-db.com/exploits/46053/unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
http://lists.opensuse.org/opensuse-security-announce/2020-04/msg00041.htmlhttps://access.redhat.com/errata/RHSA-2018:3537https://access.redhat.com/errata/RHSA-2018:3549https://access.redhat.com/errata/RHSA-2018:3551https://access.redhat.com/errata/RHSA-2018:3598https://access.redhat.com/errata/RHSA-2018:3624https://access.redhat.com/errata/RHSA-2018:3742https://access.redhat.com/errata/RHSA-2018:3752https://access.redhat.com/errata/RHSA-2018:3754https://github.com/evict/poc_CVE-2018-1002105https://github.com/kubernetes/kubernetes/issues/71411https://groups.google.com/forum/#%21topic/kubernetes-announce/GVllWCg6L88