CVE-2015-5305: Path Traversal
Directory traversal vulnerability in Kubernetes, as used in Red Hat OpenShift Enterprise 3.0, allows attackers to write to arbitrary files via a crafted object type name, which is not properly handled before passing it to etcd.
Other sources
Jordan Liggitt of Red Hat reports:
No validation is performed on the names of some object types. Because the etcd key is built directly from the object name, this allows path traversal when writing data.
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-5305?
CVE-2015-5305 is rated as a medium severity vulnerability.
How do I fix CVE-2015-5305?
To fix CVE-2015-5305, upgrade to version 1.1.1 of Kubernetes or Red Hat OpenShift Enterprise 3.0.
What causes CVE-2015-5305?
CVE-2015-5305 is caused by a directory traversal vulnerability that allows attackers to write to arbitrary files due to improper validation.
Which versions of Kubernetes are affected by CVE-2015-5305?
Kubernetes versions up to and including 1.1.1 are affected by CVE-2015-5305.
Can CVE-2015-5305 affect Red Hat OpenShift?
Yes, CVE-2015-5305 specifically affects Red Hat OpenShift Enterprise version 3.0.