CVE-2019-11246: Another kubectl Path Traversal Vulnerability Disclosed
ID: 16305668-fae0-52af-93ec-073bb2c4bfd1
STIX ID: report--16305668-fae0-52af-93ec-073bb2c4bfd1
Feed Name: Aqua Security Blog
This report documents a series of path traversal vulnerabilities in kubectl's 'cp' functionality (CVE-2018-1002100, CVE-2019-1002101, CVE-2019-11246) where a malicious or replaced tar binary, or specially crafted symlinks in a tarball, could overwrite files or enable code execution on the client; it describes the discovery timeline, shows how prior fixes were incomplete, and recommends upgrading kubectl to fixed versions (1.12.9, 1.13.6, 1.14.2) and applying container-image protections and drift prevention.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
