Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 672524 (CVE-2018-1002105) - <sys-cluster/kube-apiserver-{1.10.1, 1.11.5, 1.12.3}: proxy request handling vulnerability
Summary: <sys-cluster/kube-apiserver-{1.10.1, 1.11.5, 1.12.3}: proxy request handling ...
Status: RESOLVED FIXED
Alias: CVE-2018-1002105
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal trivial (vote)
Assignee: Gentoo Security
URL: https://github.com/kubernetes/kuberne...
Whiteboard: ~2 [noglsa cve]
Keywords:
Depends on:
Blocks:
 
Reported: 2018-12-04 20:49 UTC by D'juan McDonald (domhnall)
Modified: 2019-04-17 04:13 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description D'juan McDonald (domhnall) 2018-12-04 20:49:14 UTC
With a specially crafted request, users that are authorized to establish a connection through the Kubernetes API server to a backend server can then send arbitrary requests over the same connection directly to that backend, authenticated with the Kubernetes API server’s TLS credentials used to establish the backend connection.


@maintainer(s): Please consider dropping vulnerable versions <1.10.11

Gentoo Security Padawan
(domhnall)
Comment 1 Aaron Bauman (RETIRED) gentoo-dev 2018-12-04 21:09:40 UTC
(In reply to D'juan McDonald (domhnall) from comment #0)
> With a specially crafted request, users that are authorized to establish a
> connection through the Kubernetes API server to a backend server can then
> send arbitrary requests over the same connection directly to that backend,
> authenticated with the Kubernetes API server’s TLS credentials used to
> establish the backend connection.
> 
> 
> @maintainer(s): Please consider dropping vulnerable versions <1.10.11
> 
> Gentoo Security Padawan
> (domhnall)

Please re-read the upstream report regarding the versions which are fixed then take another look at the versions in the tree.  After that, fix this bug report.
Comment 2 D'juan McDonald (domhnall) 2018-12-05 00:20:03 UTC
Thanks to Darren Shepherd for reporting this problem.

CVE-2018-1002105 is fixed in the following Kubernetes releases:

    v1.10.11
    v1.11.5
    v1.12.3
    v1.13.0-rc.1

Affected components:

    Kubernetes API server

Affected versions:

    Kubernetes v1.0.x-1.9.x
    Kubernetes v1.10.0-1.10.10 (fixed in v1.10.11)
    Kubernetes v1.11.0-1.11.4 (fixed in v1.11.5)
    Kubernetes v1.12.0-1.12.2 (fixed in v1.12.3)
Comment 3 Aaron Bauman (RETIRED) gentoo-dev 2019-03-10 21:02:01 UTC
@maintainer, please clean the vulnerable.
Comment 4 Yury German Gentoo Infrastructure gentoo-dev 2019-04-17 04:13:36 UTC
Arches and Maintainer(s), Thank you for your work.