CVE-2018-1000400: High severity cri-o vulnerability
Kubernetes CRI-O version prior to 1.9 contains a Privilege Context Switching Error (CWE-270) vulnerability in the handling of ambient capabilities that can result in containers running with elevated privileges, allowing users abilities they should not have. This attack appears to be exploitable via container execution. This vulnerability appears to have been fixed in 1.9.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2018-1000400.
What is the severity of CVE-2018-1000400?
The severity of CVE-2018-1000400 is high.
What is the affected software for CVE-2018-1000400?
The affected software for CVE-2018-1000400 is Kubernetes CRI-O version prior to 1.9.
How does CVE-2018-1000400 impact containers?
CVE-2018-1000400 can result in containers running with elevated privileges, allowing users abilities they should not have.
Where can I find more information about CVE-2018-1000400?
You can find more information about CVE-2018-1000400 at the following references: [http://www.securityfocus.com/bid/104262](http://www.securityfocus.com/bid/104262), [https://github.com/kubernetes-incubator/cri-o/pull/1558/files](https://github.com/kubernetes-incubator/cri-o/pull/1558/files).