v1.10.13-lts.1
2 minute read
This is the first fixed release by KLTS for v1.10.13.
Patches
- CVE-2019-11245
Containers for pods that do not specify an explicit runAsUser attempt to run as uid 0 (root) on container restart, or if the image was previously pulled to the node.
- CVE-2019-1002101
This vulnerability may allow an attacker to modify or monitor any file in the directory with the same name in the symbolic link header during the unpacking process of the
kubectl cpcommand, thereby causing damage. - CVE-2019-11246
This vulnerability may allow an attacker to use the
kubectl cpcommand to write malicious files in the containertarpackage to any path on the host using Path Traversal. This process is limited only by the system permissions of the local user. - CVE-2019-11248
The debugging endpoint
/debug/pprofis exposed over the unauthenticated Kubelet healthz port. - CVE-2019-11249
This vulnerability may allow an attacker to use the
kubectl cpcommand to write malicious files in the containertarpackage to any path on the host using Path Traversal. This process is limited only by the system permissions of the local user. - CVE-2019-11251
This vulnerability may allow an attacker to use the
kubectl cpcommand to write malicious files in the containertarpackage to any path on the host using Path Traversal. This process is limited only by the system permissions of the local user. - CVE-2020-8552
This vulnerability may make the
API Servervulnerable to aDoS(Denial of Service) attack caused by successfulAPIrequests. - CVE-2021-3121
A program with this vulnerability may crash because of processing some messages that contain malicious
Protobuf. If the version ofGogo Protobufyou are using is too low, this vulnerability may exist. - nokmem
The node has sufficient disks, but it keeps reporting that the disk is insufficient to create a Pod.
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.