Red Hat Bugzilla – Bug 1273969
CVE-2015-5305 Kubernetes: Missing name validation allows path traversal in etcd
Last modified: 2015-11-05 10:18:06 EST
Jordan Liggitt of Red Hat reports: No validation is performed on the names of some object types. Because the etcd key is built directly from the object name, this allows path traversal when writing data.
Acknowledgement: This issue was discovered by Jordan Liggitt of Red Hat.
This issue has been addressed in the following products: RHEL 7 Version of OpenShift Enterprise 3.0 Via RHSA-2015:1945 https://access.redhat.com/errata/RHSA-2015:1945