Kubernetes API server follows unvalidated redirects from streaming Kubelet endpoints
Vulnerability Description
Improper validation of URL redirection in the Kubernetes API server in versions prior to v1.14.0 allows an attacker-controlled Kubelet to redirect API server requests from streaming endpoints to arbitrary hosts. Impacted API servers will follow the redirect as a GET request with client-certificate credentials for authenticating to the Kubelet.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2018-1002102
Credits & Attribution
No credits recorded in the NVD database.
References
More from Kubernetes
View All →Affected Vendor
Kubernetes
View all reports →