« Volver al listado

CVE-2019-11244

Estado: ModificadaMedia (5)—

In Kubernetes v1.8.x-v1.14.x, schema info is cached by kubectl in the location specified by --cache-dir (defaulting to $HOME/.kube/http-cache), written with world-writeable permissions (rw-rw-rw-). If --cache-dir is specified and pointed at a different location accessible to other users/groups, the written files may be modified by other users/groups and disrupt the kubectl invocation.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (3)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2019-11244",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 1.9,
          "accessVector": "LOCAL",
          "vectorString": "AV:L/AC:M/Au:N/C:N/I:P/A:N",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "LOW",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 3.4,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": true
      }
    ],
    "cvssMetricV30": [
      {
        "type": "Secondary",
        "source": "jordan@liggitt.net",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.0",
          "baseScore": 3.3,
          "attackVector": "LOCAL",
          "baseSeverity": "LOW",
          "vectorString": "CVSS:3.0/AV:L/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:N",
          "integrityImpact": "LOW",
          "userInteraction": "REQUIRED",
          "attackComplexity": "HIGH",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 2.5,
        "exploitabilityScore": 0.8
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 5,
          "attackVector": "LOCAL",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:N",
          "integrityImpact": "HIGH",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 1.3
      }
    ]
  },
  "affected": [
    {
      "source": "jordan@liggitt.net",
      "affectedData": [
        {
          "vendor": "Kubernetes",
          "product": "Kubernetes",
          "versions": [
            {
              "status": "affected",
              "version": "v1.8.0",
              "lessThan": "v1.8*",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "v1.9.0",
              "lessThan": "v1.9*",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "v1.10.0",
              "lessThan": "v1.10*",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "v1.11.0",
              "lessThan": "v1.11*",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "v1.12.0",
              "lessThan": "v1.12*",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "v1.13.0",
              "lessThan": "v1.13*",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "v1.14.0",
              "lessThan": "v1.14*",
              "versionType": "custom"
            }
          ]
        }
      ]
    }
  ],
  "published": "2019-04-22T15:29:00.837",
  "references": [
    {
      "url": "http://www.securityfocus.com/bid/108064",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "jordan@liggitt.net"
    },
    {
      "url": "https://access.redhat.com/errata/RHSA-2019:3942",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "jordan@liggitt.net"
    },
    {
      "url": "https://access.redhat.com/errata/RHSA-2020:0020",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "jordan@liggitt.net"
    },
    {
      "url": "https://access.redhat.com/errata/RHSA-2020:0074",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "jordan@liggitt.net"
    },
    {
      "url": "https://github.com/kubernetes/kubernetes/issues/76676",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "jordan@liggitt.net"
    },
    {
      "url": "https://security.netapp.com/advisory/ntap-20190509-0002/",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "jordan@liggitt.net"
    },
    {
      "url": "http://www.securityfocus.com/bid/108064",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://access.redhat.com/errata/RHSA-2019:3942",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://access.redhat.com/errata/RHSA-2020:0020",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://access.redhat.com/errata/RHSA-2020:0074",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://github.com/kubernetes/kubernetes/issues/76676",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://security.netapp.com/advisory/ntap-20190509-0002/",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "jordan@liggitt.net",
      "description": [
        {
          "lang": "en",
          "value": "CWE-524"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-732"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "In Kubernetes v1.8.x-v1.14.x, schema info is cached by kubectl in the location specified by --cache-dir (defaulting to $HOME/.kube/http-cache), written with world-writeable permissions (rw-rw-rw-). If --cache-dir is specified and pointed at a different location accessible to other users/groups, the written files may be modified by other users/groups and disrupt the kubectl invocation."
    },
    {
      "lang": "es",
      "value": "En Kubernetes versión 1.8.x hasta versión 1.14.x, el componente kubectl almacena en caché la información del esquema en la ubicación especificada por --cache-dir (defaulting to $HOME/.kube/http-cache), escrita con permisos world-writeable (rw-rw-rw-). Si se especifica --cache-dir y se apunta a una ubicación distinta accesible para otros usuarios o grupos, los archivos escritos pueden ser modificados por otros usuarios o grupos e interrumpir la invocación de Kubectl."
    }
  ],
  "lastModified": "2026-06-17T02:12:36.310",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:kubernetes:kubernetes:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A57F3AC4-5E09-4C16-91A7-80D54F8F968C",
              "versionEndIncluding": "1.14.1",
              "versionStartIncluding": "1.8.0"
            }
          ],
          "operator": "OR"
        }
      ]
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:netapp:trident:-:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5D9A34F5-AC03-4098-A37D-AD50727DDB11"
            }
          ],
          "operator": "OR"
        }
      ]
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:redhat:openshift_container_platform:3.11:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2F87326E-0B56-4356-A889-73D026DB1D4B"
            },
            {
              "criteria": "cpe:2.3:a:redhat:openshift_container_platform:4.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "064E7BDD-4EF0-4A0D-A38D-8C75BAFEDCEF"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "jordan@liggitt.net"
}