First published: Thu Jan 03 2019(Updated: )
Kubernetes Dashboard before 1.10.1 allows attackers to bypass authentication and use Dashboard's Service Account for reading secrets within the cluster.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Kubernetes Dashboard | <1.10.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-18264 is considered a high severity vulnerability due to its ability to bypass authentication and access sensitive information.
To fix CVE-2018-18264, upgrade Kubernetes Dashboard to version 1.10.1 or higher.
CVE-2018-18264 allows unauthorized users to read secrets within the Kubernetes cluster, compromising security.
Kubernetes Dashboard versions prior to 1.10.1 are affected by CVE-2018-18264.
Yes, CVE-2018-18264 can potentially be exploited remotely if the Kubernetes Dashboard is exposed to the internet.