GPU VulnDB

Database/Container, Kubernetes & orchestration

Kubernetes (kubectl): `kubectl cp` path traversal from a malicious container tar overwrites files on the operator's

CVE-2019-11246Container, Kubernetes & orchestrationcurated

Impact

kubectl cp path traversal from a malicious container tar overwrites files on the operator's workstation

Who can reach it

Malicious image, triggered when an operator runs kubectl cp

What to do

Upgrade kubectl on all operator and CI machines; not a cluster change

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.