Back to search

CVE-2017-1002100

MEDIUM
6.5NVD

Default access permissions for Persistent Volumes (PVs) created by the Kubernetes Azure cloud provider in versions 1.6.0 to 1.6.5 are set to "container" which exposes a URI that can be accessed without authentication on the public internet. Access to the URI string requires privileged access to the Kubernetes cluster or authenticated access to the Azure portal.

CVSS v3.0 Score

6.5
/ 10.0
MEDIUM
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Information

Published
14 sept. 2017
Updated
20 avr. 2025
Status
Deferred
Source
jordan@liggitt.net

Affected products

kubernetes kubernetesAll Kubernetes CVEs →
Versions : 1.6.0, 1.6.1, 1.6.2, 1.6.3, 1.6.4

Weaknesses (CWE)

CWE-200

Similar CVEs

Other vulnerabilities of type CWE-200

Loading…

Monitor your products

Get automatic alerts for every new CVE affecting your equipment.

Enable monitoring