Severe Privilege Escalation Vulnerability in Kubernetes (CVE-2018-1002105)
ID: 44b8ef82-af1e-5ab0-aafc-b72ec271a52f
STIX ID: report--44b8ef82-af1e-5ab0-aafc-b72ec271a52f
Feed Name: Aqua Security Blog
Threat Score
This advisory details CVE-2018-1002105, a critical Kubernetes API server vulnerability (CVSS 9.8) that enables unauthenticated remote privilege escalation to full cluster admin by abusing pod exec/attach/portforward and aggregated API server endpoints; it lists affected versions, fixed releases, recommended mitigations (upgrade clusters, use kube-hunter/kube-bench, deploy Aqua enforcers), and emphasizes the severe impact of complete cluster takeover.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
