DirectorySecurity Advisories
Sign In
Security Advisories

CGA-vcfc-378w-j2p8

Published

Last updated

https://images.chainguard.dev/security/CGA-vcfc-378w-j2p8
Package

kubeflow-pipelines

Latest Update
Not affected
Aliases
  • CVE-2018-1002101
  • GHSA-wqwf-x5cj-rg56

Severity

5.9

Medium

CVSS V3

Summary

Kubernetes Arbitrary Command Injection

Description

In Kubernetes versions 1.9.0-1.9.9, 1.10.0-1.10.5, and 1.11.0-1.11.1, user input was handled insecurely while setting up volume mounts on Windows nodes, which could lead to command line argument injection.

Specific Go Packages Affected

k8s.io/kubernetes/pkg/util/mount

References

Updates


Safe Source for Open Sourceâ„¢
Media KitContact Us
© 2024 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Product

Chainguard Images