/
DirectorySecurity AdvisoriesPricing
Sign In
Security Advisories

CVE-2018-1002102

Published

Last updated

NVD

https://nvd.nist.gov/vuln/detail/CVE-2018-1002102

Severity

Unknown

Description

Improper validation of URL redirection in the Kubernetes API server in versions prior to v1.14.0 allows an attacker-controlled Kubelet to redirect API server requests from streaming endpoints to arbitrary hosts. Impacted API servers will follow the redirect as a GET request with client-certificate credentials for authenticating to the Kubelet.

References

  • https://images.chainguard.dev/security/CGA-4xmg-fgrg-2hvg

Affected packages


Safe Source for Open Sourceâ„¢
Media KitContact Us
© 2025 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Products

Chainguard ContainersChainguard LibrariesChainguard VMs