CVE-2018-1002105 Details
Description
In all Kubernetes versions prior to v1.10.11, v1.11.5, and v1.12.3, incorrect handling of error responses to proxied upgrade requests in the kube-apiserver allowed specially crafted requests to establish a connection through the Kubernetes API server to backend servers, then send arbitrary requests over the same connection directly to the backend, authenticated with the Kubernetes API server's TLS credentials used to establish the backend connection.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-388 | 7PK - Errors | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| kubernetes kubernetes | >= 1.0.0, <= 1.9.11 >= 1.10.0, <= 1.10.10 >= 1.11.0, <= 1.11.4 >= 1.12.0, <= 1.12.2 1.9.12 beta0 |
CPE
Remediation
| |
| redhat openshift container platform | 3.2 3.3 3.4 3.5 3.6 3.8 3.10 3.11 |
CPE
Remediation
| |
| netapp trident | All versions |
CPE
Remediation
| |
Change History
16 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Nov 21, 2024 | CVE Modified | CVE |
| May 14, 2024 | CVE Modified | [email protected] |
| Nov 7, 2023 | CVE Modified | [email protected] |
| Apr 26, 2020 | CVE Modified | [email protected] |
| Oct 9, 2019 | CVE Modified | [email protected] |
| Jul 7, 2019 | CVE Modified | [email protected] |
| Jun 28, 2019 | CVE Modified | [email protected] |
| Apr 25, 2019 | Modified Analysis | [email protected] |
| Apr 16, 2019 | CVE Modified | [email protected] |
| Mar 7, 2019 | Modified Analysis | [email protected] |
| Feb 6, 2019 | CVE Modified | [email protected] |
| Dec 25, 2018 | CVE Modified | [email protected] |
| Dec 11, 2018 | Initial Analysis | [email protected] |
| Dec 7, 2018 | CVE Modified | [email protected] |
| Dec 6, 2018 | CVE Modified | [email protected] |