Hacker Newsnew | past | comments | ask | show | jobs | submitlogin
Critical Privilege Escalation Flaw Patched in Kubernetes (securityweek.com)
5 points by edejong on Dec 4, 2018 | hide | past | favorite | 1 comment


Heads up, this is a critical Kubernetes security vulnerability that can be exploited without any credentials via a network vector and without leaving a trace.

It fixes Kubernetes issue 71411 [1]: CVE-2018-1002105: proxy request handling in kube-apiserver can leave vulnerable TCP connections.

https://github.com/kubernetes/kubernetes/issues/71411




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: