Back

MEDIUM

kubectl creates world-writeable cached schema files

Published Apr 22, 2019

Description

In Kubernetes v1.8.x-v1.14.x, schema info is cached by kubectl in the location specified by --cache-dir (defaulting to $HOME/.kube/http-cache), written with world-writeable permissions (rw-rw-rw-). If --cache-dir is specified and pointed at a different location accessible to other users/groups, the written files may be modified by other users/groups and disrupt the kubectl invocation.

Affected products

Remediation

Vendor solution

Use the default --http-cache location in the $HOME directory or point it at a directory that is only accessible to desired users/groups.

Red Hat statement

OpenShift Container Platform includes kubectl. OCP 3.9 and later include this same flaw. This issue does not affect the version of Kubernetes (embedded in heketi) shipped with Red Hat Gluster Storage 3 as it does not contain the vulnerable functionality.

Red Hat mitigation

Do not use --cache-dir, or ensure that --cache-dir is not set to a location that other users have access to.

Metrics

References (14)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner kubernetes
Published Apr 22, 2019
Updated Aug 4, 2024
Reserved Apr 17, 2019
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Low
Public date Apr 22, 2019
GHSA-2575-PGHM-6QQX