First published: Fri May 18 2018(Updated: )
Kubernetes CRI-O version prior to 1.9 contains a Privilege Context Switching Error (CWE-270) vulnerability in the handling of ambient capabilities that can result in containers running with elevated privileges, allowing users abilities they should not have. This attack appears to be exploitable via container execution. This vulnerability appears to have been fixed in 1.9.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Kubernetes CRI-O | <1.9.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this vulnerability is CVE-2018-1000400.
The severity of CVE-2018-1000400 is high.
The affected software for CVE-2018-1000400 is Kubernetes CRI-O version prior to 1.9.
CVE-2018-1000400 can result in containers running with elevated privileges, allowing users abilities they should not have.
You can find more information about CVE-2018-1000400 at the following references: [http://www.securityfocus.com/bid/104262](http://www.securityfocus.com/bid/104262), [https://github.com/kubernetes-incubator/cri-o/pull/1558/files](https://github.com/kubernetes-incubator/cri-o/pull/1558/files).