GHSA-wqwf-x5cj-rg56

Suggest an improvement
Source
https://github.com/advisories/GHSA-wqwf-x5cj-rg56
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/02/GHSA-wqwf-x5cj-rg56/GHSA-wqwf-x5cj-rg56.json
JSON Data
https://api.test.osv.dev/v1/vulns/GHSA-wqwf-x5cj-rg56
Aliases
Related
Published
2022-02-15T01:57:18Z
Modified
2024-09-11T06:13:31.352181Z
Severity
  • 5.9 (Medium) CVSS_V3 - CVSS:3.0/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N CVSS Calculator
Summary
Kubernetes Arbitrary Command Injection
Details

In Kubernetes versions 1.9.0-1.9.9, 1.10.0-1.10.5, and 1.11.0-1.11.1, user input was handled insecurely while setting up volume mounts on Windows nodes, which could lead to command line argument injection.

Specific Go Packages Affected

k8s.io/kubernetes/pkg/util/mount

Database specific
{
    "nvd_published_at": null,
    "cwe_ids": [
        "CWE-78"
    ],
    "severity": "MODERATE",
    "github_reviewed": true,
    "github_reviewed_at": "2021-05-12T18:22:09Z"
}
References

Affected packages

Go / k8s.io/kubernetes

Package

Name
k8s.io/kubernetes
View open source insights on deps.dev
Purl
pkg:golang/k8s.io/kubernetes

Affected ranges

Type
SEMVER
Events
Introduced
1.9.0
Fixed
1.9.10

Go / k8s.io/kubernetes

Package

Name
k8s.io/kubernetes
View open source insights on deps.dev
Purl
pkg:golang/k8s.io/kubernetes

Affected ranges

Type
SEMVER
Events
Introduced
1.10.0
Fixed
1.10.6

Go / k8s.io/kubernetes

Package

Name
k8s.io/kubernetes
View open source insights on deps.dev
Purl
pkg:golang/k8s.io/kubernetes

Affected ranges

Type
SEMVER
Events
Introduced
1.11.0
Fixed
1.11.2