7.1

CVE-2017-1002102

In Kubernetes versions 1.3.x, 1.4.x, 1.5.x, 1.6.x and prior to versions 1.7.14, 1.8.9 and 1.9.4 containers using a secret, configMap, projected or downwardAPI volume can trigger deletion of arbitrary files/directories from the nodes where they are running.

Data is provided by the National Vulnerability Database (NVD)
KubernetesKubernetes Version >= 1.3.0 <= 1.3.10
KubernetesKubernetes Version >= 1.4.0 <= 1.4.12
KubernetesKubernetes Version >= 1.5.0 <= 1.5.8
KubernetesKubernetes Version >= 1.6.0 <= 1.6.13
KubernetesKubernetes Version >= 1.7.0 < 1.7.14
KubernetesKubernetes Version >= 1.8.0 < 1.8.9
KubernetesKubernetes Version >= 1.9.0 < 1.9.4
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.4% 0.601
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 5.6 1.1 4
CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:C/C:N/I:H/A:N
nvd@nist.gov 6.3 3.4 9.2
AV:L/AC:M/Au:N/C:N/I:C/A:C
jordan@liggitt.net 7.1 2.8 4.2
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H