CVE-2019-11247
Kubernetes kube-apiserver unauthorized access
8.1
HIGH
CVSS 3.1
EPSS 2.1%
描述
The Kubernetes kube-apiserver mistakenly allows access to a cluster-scoped custom resource if the request is made as if the resource were namespaced. Authorizations for the resource accessed in this manner are enforced using roles and role bindings within the namespace, meaning that a user with access only to a resource in one namespace could create, view update or delete the cluster-scoped resource (according to their namespace role privileges). Kubernetes affected versions include versions prior to 1.13.9, versions prior to 1.14.5, versions prior to 1.15.2, and versions 1.7, 1.8, 1.9, 1.10, 1.11, 1.12.
如何修補 CVE-2019-11247
要修補 CVE-2019-11247,請將受影響套件升級到下列已修補版本。
- —升級至 1.17.4-1 或更新版本
- —升級至 0.13.9 或更新版本
CVE-2019-11247 正在被利用嗎?
低 — EPSS 為 2.1%,目前沒有觀察到大規模利用活動。
受影響套件(2)
- from 0, < 1.17.4-1
- >= 0.7.0, < 0.13.9
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH8.1 | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N |