kubectl creates world-writeable cached schema files
Published Apr 22, 2019
5.0
MEDIUMCVSS 3.1
EPSS 0.50%
Description
In Kubernetes v1.8.x-v1.14.x, schema info is cached by kubectl in the location specified by --cache-dir (defaulting to $HOME/.kube/http-cache), written with world-writeable permissions (rw-rw-rw-). If --cache-dir is specified and pointed at a different location accessible to other users/groups, the written files may be modified by other users/groups and disrupt the kubectl invocation.
Affected products
-
- Version v1.10.0StatusaffectedConstraints<v1.10*
- Version v1.11.0StatusaffectedConstraints<v1.11*
- Version v1.12.0StatusaffectedConstraints<v1.12*
- Version v1.13.0StatusaffectedConstraints<v1.13*
- Version v1.14.0StatusaffectedConstraints<v1.14*
- Version v1.8.0StatusaffectedConstraints<v1.8*
- Version v1.9.0StatusaffectedConstraints<v1.9*
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Kubernetes | Kubernetes | n/a |
|
Configuration 1
- ≥ 1.8.0 · ≤ 1.14.1
Configuration 3
- 3.11
- 4.1
No data.
Red Hat OpenShift Container Platform 3.11
atomic-openshift-0:3.11.161-1.git.0.4ccbe25.el7
Fixed · RHSA-2020:0020
Red Hat OpenShift Container Platform 4.1
openshift-0:4.1.24-201911080309.git.0.c41acf2.el7
Fixed · RHSA-2019:3942
Red Hat OpenShift Container Platform 4.1
openshift4/ose-cli:v4.1.24-201911120311
Fixed · RHSA-2020:0074
Red Hat OpenShift Container Platform 3.10
atomic-openshift
Affected
Red Hat OpenShift Container Platform 3.6
atomic-openshift
Not affected
Red Hat OpenShift Container Platform 3.7
atomic-openshift
Not affected
Red Hat OpenShift Container Platform 3.9
atomic-openshift
Affected
Red Hat Storage 3
heketi
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat OpenShift Container Platform 3.11 | atomic-openshift-0:3.11.161-1.git.0.4ccbe25.el7 | Fixed | RHSA-2020:0020 |
| Red Hat OpenShift Container Platform 4.1 | openshift-0:4.1.24-201911080309.git.0.c41acf2.el7 | Fixed | RHSA-2019:3942 |
| Red Hat OpenShift Container Platform 4.1 | openshift4/ose-cli:v4.1.24-201911120311 | Fixed | RHSA-2020:0074 |
| Red Hat OpenShift Container Platform 3.10 | atomic-openshift | Affected | n/a |
| Red Hat OpenShift Container Platform 3.6 | atomic-openshift | Not affected | n/a |
| Red Hat OpenShift Container Platform 3.7 | atomic-openshift | Not affected | n/a |
| Red Hat OpenShift Container Platform 3.9 | atomic-openshift | Affected | n/a |
| Red Hat Storage 3 | heketi | Not affected | n/a |
k8s.io/client-go
Go
Introduced 1.8.0 Fixed 1.12.9
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| Go | k8s.io/client-go | 1.8.0 | 1.12.9 |
Remediation
Vendor solution
Use the default --http-cache location in the $HOME directory or point it at a directory that is only accessible to desired users/groups.
Red Hat statement
OpenShift Container Platform includes kubectl. OCP 3.9 and later include this same flaw. This issue does not affect the version of Kubernetes (embedded in heketi) shipped with Red Hat Gluster Storage 3 as it does not contain the vulnerable functionality.
Red Hat mitigation
Do not use --cache-dir, or ensure that --cache-dir is not set to a location that other users have access to.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:N
CVSS:3.0/AV:L/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:N
AV:L/AC:M/Au:N/C:N/I:P/A:N
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v5
- EPSS v2
- EPSS v3
- EPSS v4
Percentile over time
- EPSS v1
- EPSS v5
- EPSS v2
- EPSS v3
- EPSS v4
Table of values (12 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 0.50% (0.00502) | 40.68th | v5 (v2026.06.15) |
| Jun 15, 2026 | 0.48% (0.00479) | 37.38th | v5 (v2026.06.15) |
| Mar 17, 2025 | 0.11% (0.00110) | 27.00th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.08% (0.00077) | 35.00th | v3 (v2023.03.01) |
| Apr 15, 2024 | 0.08% (0.00077) | 32.02th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.05% (0.00046) | 14.11th | v3 (v2023.03.01) |
| Mar 6, 2023 | 1.03% (0.01034) | 41.69th | v2 (v2022.01.01) |
| Feb 4, 2022 | 2.01% (0.02008) | 56.41th | v2 (v2022.01.01) |
| Feb 3, 2022 | 6.21% (0.06208) | 81.93th | v1 |
| Jan 6, 2022 | 6.21% (0.06208) | 81.75th | v1 |
| Jan 5, 2022 | 1.45% (0.01454) | 72.86th | v5 (v2026.06.15) |
| Apr 14, 2021 | 1.45% (0.01454) | 0.00th | v1 |
References (14)
- http://www.securityfocus.com/bid/108064 vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry
- https://access.redhat.com/errata/RHSA-2019:3942 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2020:0020 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2020:0074 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2019-11244 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1703209 Issue Tracking
- https://github.com/advisories/GHSA-2575-pghm-6qqx Advisory
- https://github.com/kubernetes/client-go/commit/790a4f63632139cf6731014d00a9a8338f1fbd7d
- https://github.com/kubernetes/kubernetes/issues/76676 x_refsource_MISCThird Party Advisory
- https://github.com/kubernetes/kubernetes/pull/77874
- https://github.com/kubernetes/kubernetes/pull/77874/commits/f228ae3364729caed59087e23c42868454bc3ff4
- https://nvd.nist.gov/vuln/detail/CVE-2019-11244
- https://security.netapp.com/advisory/ntap-20190509-0002/ x_refsource_CONFIRMThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2019-11244
Change history (0)
No recorded changes yet.