Red Hat Bugzilla – Bug 1564305
CVE-2018-1002100 kubernetes: Kubectl copy doesn't check for paths outside of it's destination directory
Last modified: 2018-10-27 17:43:12 EDT
When using kubectl to cp files to a pod, if the container returns a malformed tarfile with paths like, '/some/remote/dir/../../../../tmp/foo' kubectl writes this to /tmp/foo instead of /some/local/dir/tmp/foo. https://github.com/kubernetes/kubernetes/issues/61297
Acknowledgments: Name: Michael Hanselmann (hansmi.ch)
Created kubernetes tracking bugs for this issue: Affects: fedora-all [bug 1564307]
Statement: Kubernetes support is moving from Red Hat Enterprise Linux to OpenShift Container Platform. Kubernetes and its dependencies will no longer be updated through the Extras channel. Instead, the Red Hat customers are advised to use Red Hat's supported Kubernetes-based products such as Red Hat OpenShift Container Platform.