CVE-2018-1002105

UnknownEPSS 86.98%

Last modified

CVE-2018-1002105 is a vulnerability of currently unknown severity. In all Kubernetes versions prior to v1.10.11, v1.11.5, and v1.12.3, incorrect handling of error responses to proxied upgrade requests in the kube-apiserver allowed specially crafted requests to establish a connection through the Kubernetes API server to backend servers, then send arbitrary requests over the same connection directly to the backend, authenticated with the Kubernetes API server's TLS credentials used to establish the backend connection.. EPSS estimates a 86.98% chance of exploitation in the next 30 days.

Description

In all Kubernetes versions prior to v1.10.11, v1.11.5, and v1.12.3, incorrect handling of error responses to proxied upgrade requests in the kube-apiserver allowed specially crafted requests to establish a connection through the Kubernetes API server to backend servers, then send arbitrary requests over the same connection directly to the backend, authenticated with the Kubernetes API server's TLS credentials used to establish the backend connection.

Metrics

EPSS Probability
86.98%

99.7th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersionsUpdate
KubernetesKubernetes>= 1.0.0, <= 1.9.11
KubernetesKubernetes>= 1.10.0, <= 1.10.10
KubernetesKubernetes>= 1.11.0, <= 1.11.4
KubernetesKubernetes>= 1.12.0, <= 1.12.2
KubernetesKubernetes1.9.12Beta0
RedhatOpenshift Container Platform3.2
RedhatOpenshift Container Platform3.3
RedhatOpenshift Container Platform3.4
RedhatOpenshift Container Platform3.5
RedhatOpenshift Container Platform3.6
RedhatOpenshift Container Platform3.8
RedhatOpenshift Container Platform3.10
RedhatOpenshift Container Platform3.11
NetappTridentAll versions

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2018-1002105?
In all Kubernetes versions prior to v1.10.11, v1.11.5, and v1.12.3, incorrect handling of error responses to proxied upgrade requests in the kube-apiserver allowed specially crafted requests to establish a connection through the Kubernetes API server to backend servers, then send arbitrary requests over the same connection directly to the backend, authenticated with the Kubernetes API server's TLS credentials used to establish the backend connection.
How severe is CVE-2018-1002105?
Severity scoring for CVE-2018-1002105 is pending analysis. The EPSS model estimates a 86.98% probability of exploitation in the next 30 days.
How do I fix CVE-2018-1002105?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2018-1002105?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST