logo

CVE-2019-11246: Another kubectl Path Traversal Vulnerability Disclosed

ID: 16305668-fae0-52af-93ec-073bb2c4bfd1

STIX ID: report--16305668-fae0-52af-93ec-073bb2c4bfd1

Feed Name: Aqua Security Blog

Threat Score
55/100

Date Published: 2019-06-27

Date Updated: 2026-04-26

...
...

This report documents a series of path traversal vulnerabilities in kubectl's 'cp' functionality (CVE-2018-1002100, CVE-2019-1002101, CVE-2019-11246) where a malicious or replaced tar binary, or specially crafted symlinks in a tarball, could overwrite files or enable code execution on the client; it describes the discovery timeline, shows how prior fixes were incomplete, and recommends upgrading kubectl to fixed versions (1.12.9, 1.13.6, 1.14.2) and applying container-image protections and drift prevention.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.