Bug 1721704 (CVE-2019-11246)
Summary: | CVE-2019-11246 kubernetes: Incomplete fix for CVE-2019-1002101 allows for arbitrary file write via `kubectl cp` | ||
---|---|---|---|
Product: | [Other] Security Response | Reporter: | Sam Fowler <sfowler> |
Component: | vulnerability | Assignee: | Red Hat Product Security <security-response-team> |
Status: | CLOSED ERRATA | QA Contact: | |
Severity: | medium | Docs Contact: | |
Priority: | medium | ||
Version: | unspecified | CC: | admiller, ahardin, bleanhar, bmontgom, ccoleman, dedgar, eparis, go-sig, hchiramm, hvyas, ichavero, jbrooks, jburrell, jcajka, jchaloup, jgoulding, jmulligan, jokerman, kramdoss, madam, mchappel, mmariyan, nhorman, nstielau, rhs-bugs, sankarshan, security-response-team, sisharma, sponnaga, ssaha, storage-qa-internal, strigazi, tstclair, vbatts, vbellur |
Target Milestone: | --- | Keywords: | Security |
Target Release: | --- | ||
Hardware: | All | ||
OS: | Linux | ||
Whiteboard: | |||
Fixed In Version: | kubernetes 1.12.9, kubernetes 1.13.6, kubernetes 1.14.2 | Doc Type: | If docs needed, set a value |
Doc Text: | Story Points: | --- | |
Clone Of: | Environment: | ||
Last Closed: | 2019-07-12 13:07:50 UTC | Type: | --- |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: | |||
Bug Depends On: | 1721756, 1721757, 1721758, 1721759, 1721773, 1722682, 1722683, 1722684, 1722824 | ||
Bug Blocks: | 1721706 |
Description
Sam Fowler
2019-06-18 22:14:38 UTC
Acknowledgments: Name: the Kubernetes Product Security Committee Upstream: Charles Holmes (Atredis Partners) External Reference: https://groups.google.com/forum/#!topic/kubernetes-dev/OxFMDVnqk60 Created kubernetes tracking bugs for this issue: Affects: fedora-all [bug 1722684] Created kubernetes:1.10/kubernetes tracking bugs for this issue: Affects: fedora-all [bug 1722682] Created kubernetes:openshift-3.10/origin tracking bugs for this issue: Affects: fedora-all [bug 1722683] In Gluster, kubernetes version embedded with heketi is older than 1.12.9. Filed trackers, this may end up WONTFIX as kubernetes is not used directly by Gluster. This issue has been addressed in the following products: Red Hat OpenShift Container Platform 3.10 Via RHSA-2019:1632 https://access.redhat.com/errata/RHSA-2019:1632 This issue has been addressed in the following products: Red Hat OpenShift Container Platform 3.11 Via RHSA-2019:1633 https://access.redhat.com/errata/RHSA-2019:1633 This bug is now closed. Further updates for individual products will be reflected on the CVE page(s): https://access.redhat.com/security/cve/cve-2019-11246 This issue has been addressed in the following products: Red Hat OpenShift Container Platform 3.9 Via RHSA-2019:1852 https://access.redhat.com/errata/RHSA-2019:1852 |