CVE-2018-18264: High severity kubernetes dashboard vulnerability
Published Jan 3, 2019
·Updated
Kubernetes Dashboard before 1.10.1 allows attackers to bypass authentication and use Dashboard's Service Account for reading secrets within the cluster.
Affected Software
1 affected component
Kubernetes Dashboard<1.10.1
Remediation
Patch Available
Patch Available
Event History
Jan 3, 2019
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-18264?
CVE-2018-18264 is considered a high severity vulnerability due to its ability to bypass authentication and access sensitive information.
2
How do I fix CVE-2018-18264?
To fix CVE-2018-18264, upgrade Kubernetes Dashboard to version 1.10.1 or higher.
3
What impact does CVE-2018-18264 have on Kubernetes clusters?
CVE-2018-18264 allows unauthorized users to read secrets within the Kubernetes cluster, compromising security.
4
Which versions of Kubernetes Dashboard are affected by CVE-2018-18264?
Kubernetes Dashboard versions prior to 1.10.1 are affected by CVE-2018-18264.
5
Can CVE-2018-18264 be exploited remotely?
Yes, CVE-2018-18264 can potentially be exploited remotely if the Kubernetes Dashboard is exposed to the internet.