Kubernetes kube-apiserver allows access to custom resources via wrong scope
Published Aug 29, 2019
8.1
HIGHCVSS 3.1
EPSS 2.15%
Description
The Kubernetes kube-apiserver mistakenly allows access to a cluster-scoped custom resource if the request is made as if the resource were namespaced. Authorizations for the resource accessed in this manner are enforced using roles and role bindings within the namespace, meaning that a user with access only to a resource in one namespace could create, view update or delete the cluster-scoped resource (according to their namespace role privileges). Kubernetes affected versions include versions prior to 1.13.9, versions prior to 1.14.5, versions prior to 1.15.2, and versions 1.7, 1.8, 1.9, 1.10, 1.11, 1.12.
Affected products
-
- Version 1.10StatusaffectedConstraints-
- Version 1.11StatusaffectedConstraints-
- Version 1.12StatusaffectedConstraints-
- Version 1.7StatusaffectedConstraints-
- Version 1.8StatusaffectedConstraints-
- Version 1.9StatusaffectedConstraints-
- Version prior to 1.13.9StatusaffectedConstraints-
- Version prior to 1.14.5StatusaffectedConstraints-
- Version prior to 1.15.2StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Kubernetes | Kubernetes | n/a |
|
Configuration 1
- ≥ 1.7.0 · ≤ 1.12.10
- ≥ 1.13.0 · < 1.13.9
- ≥ 1.14.0 · < 1.14.5
- ≥ 1.15.0 · < 1.15.2
- 1.12.11
Configuration 2
- 3.9
- 3.10
- 3.11
No data.
Red Hat OpenShift Container Platform 3.10
atomic-openshift-0:3.10.170-1.git.0.8e592d6.el7
Fixed · RHSA-2019:2690
Red Hat OpenShift Container Platform 3.11
ansible-service-broker-1:1.3.23-2.el7
Fixed · RHBA-2019:2816
Red Hat OpenShift Container Platform 3.9
ansible-service-broker-0:1.1.20-2.el7
Fixed · RHSA-2019:2769
Red Hat OpenShift Container Platform 3.9
atomic-openshift-0:3.9.101-1.git.0.150f595.el7
Fixed · RHSA-2019:2769
Red Hat OpenShift Container Platform 3.9
atomic-openshift-descheduler-0:3.9.13-2.git.267.bb59a3f.el7
Fixed · RHSA-2019:2769
Red Hat OpenShift Container Platform 3.9
atomic-openshift-dockerregistry-0:3.9.101-1.git.1.13625cf.el7
Fixed · RHSA-2019:2769
Red Hat OpenShift Container Platform 3.9
atomic-openshift-node-problem-detector-0:3.9.13-2.git.167.5d6b0d4.el7
Fixed · RHSA-2019:2769
Red Hat OpenShift Container Platform 3.9
atomic-openshift-web-console-0:3.9.101-1.git.1.601c6d2.el7
Fixed · RHSA-2019:2769
Red Hat OpenShift Container Platform 3.9
cockpit-0:195-2.rhaos.el7
Fixed · RHSA-2019:2769
Red Hat OpenShift Container Platform 3.9
containernetworking-plugins-0:0.5.2-6.el7
Fixed · RHSA-2019:2769
Red Hat OpenShift Container Platform 3.9
cri-o-0:1.9.16-3.git858756d.el7
Fixed · RHSA-2019:2769
Red Hat OpenShift Container Platform 3.9
cri-tools-0:1.0.0-6.rhaos3.9.git8e6013a.el7
Fixed · RHSA-2019:2769
Red Hat OpenShift Container Platform 3.9
golang-github-openshift-oauth-proxy-0:2.1-3.git885c9f40.el7
Fixed · RHSA-2019:2769
Red Hat OpenShift Container Platform 3.9
golang-github-openshift-prometheus-alert-buffer-0:0-3.gitceca8c1.el7
Fixed · RHSA-2019:2769
Red Hat OpenShift Container Platform 3.9
golang-github-prometheus-alertmanager-0:0.14.0-2.git30af4d0.el7
Fixed · RHSA-2019:2769
Red Hat OpenShift Container Platform 3.9
golang-github-prometheus-node_exporter-0:3.9.101-1.git.1.8295224.el7
Fixed · RHSA-2019:2769
Red Hat OpenShift Container Platform 3.9
golang-github-prometheus-prometheus-0:2.2.1-2.gitbc6058c.el7
Fixed · RHSA-2019:2769
Red Hat OpenShift Container Platform 3.9
golang-github-prometheus-promu-0:0-5.git85ceabc.el7
Fixed · RHSA-2019:2769
Red Hat OpenShift Container Platform 3.9
hawkular-openshift-agent-0:1.2.2-3.el7
Fixed · RHSA-2019:2769
Red Hat OpenShift Container Platform 3.9
heapster-0:1.3.0-4.el7
Fixed · RHSA-2019:2769
Red Hat OpenShift Container Platform 3.9
image-inspector-0:2.1.3-2.el7
Fixed · RHSA-2019:2769
Red Hat OpenShift Container Platform 3.9
openshift-enterprise-image-registry-0:3.8.0-2.git.216.b6b90bb.el7
Fixed · RHSA-2019:2769
Red Hat OpenShift Container Platform 3.9
openshift-eventrouter-0:0.1-3.git5bd9251.el7
Fixed · RHSA-2019:2769
Red Hat OpenShift Container Platform 3.9
openshift-external-storage-0:0.0.1-9.git78d6339.el7
Fixed · RHSA-2019:2769
Red Hat OpenShift Container Platform 3.9
openvswitch-ovn-kubernetes-0:0.1.0-3.el7
Fixed · RHSA-2019:2769
Red Hat OpenShift Container Platform 4.1
openshift-0:4.1.10-201908060758.git.0.d81afa6.el7
Fixed · RHSA-2019:2504
Red Hat Storage 3
heketi
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat OpenShift Container Platform 3.10 | atomic-openshift-0:3.10.170-1.git.0.8e592d6.el7 | Fixed | RHSA-2019:2690 |
| Red Hat OpenShift Container Platform 3.11 | ansible-service-broker-1:1.3.23-2.el7 | Fixed | RHBA-2019:2816 |
| Red Hat OpenShift Container Platform 3.9 | ansible-service-broker-0:1.1.20-2.el7 | Fixed | RHSA-2019:2769 |
| Red Hat OpenShift Container Platform 3.9 | atomic-openshift-0:3.9.101-1.git.0.150f595.el7 | Fixed | RHSA-2019:2769 |
| Red Hat OpenShift Container Platform 3.9 | atomic-openshift-descheduler-0:3.9.13-2.git.267.bb59a3f.el7 | Fixed | RHSA-2019:2769 |
| Red Hat OpenShift Container Platform 3.9 | atomic-openshift-dockerregistry-0:3.9.101-1.git.1.13625cf.el7 | Fixed | RHSA-2019:2769 |
| Red Hat OpenShift Container Platform 3.9 | atomic-openshift-node-problem-detector-0:3.9.13-2.git.167.5d6b0d4.el7 | Fixed | RHSA-2019:2769 |
| Red Hat OpenShift Container Platform 3.9 | atomic-openshift-web-console-0:3.9.101-1.git.1.601c6d2.el7 | Fixed | RHSA-2019:2769 |
| Red Hat OpenShift Container Platform 3.9 | cockpit-0:195-2.rhaos.el7 | Fixed | RHSA-2019:2769 |
| Red Hat OpenShift Container Platform 3.9 | containernetworking-plugins-0:0.5.2-6.el7 | Fixed | RHSA-2019:2769 |
| Red Hat OpenShift Container Platform 3.9 | cri-o-0:1.9.16-3.git858756d.el7 | Fixed | RHSA-2019:2769 |
| Red Hat OpenShift Container Platform 3.9 | cri-tools-0:1.0.0-6.rhaos3.9.git8e6013a.el7 | Fixed | RHSA-2019:2769 |
| Red Hat OpenShift Container Platform 3.9 | golang-github-openshift-oauth-proxy-0:2.1-3.git885c9f40.el7 | Fixed | RHSA-2019:2769 |
| Red Hat OpenShift Container Platform 3.9 | golang-github-openshift-prometheus-alert-buffer-0:0-3.gitceca8c1.el7 | Fixed | RHSA-2019:2769 |
| Red Hat OpenShift Container Platform 3.9 | golang-github-prometheus-alertmanager-0:0.14.0-2.git30af4d0.el7 | Fixed | RHSA-2019:2769 |
| Red Hat OpenShift Container Platform 3.9 | golang-github-prometheus-node_exporter-0:3.9.101-1.git.1.8295224.el7 | Fixed | RHSA-2019:2769 |
| Red Hat OpenShift Container Platform 3.9 | golang-github-prometheus-prometheus-0:2.2.1-2.gitbc6058c.el7 | Fixed | RHSA-2019:2769 |
| Red Hat OpenShift Container Platform 3.9 | golang-github-prometheus-promu-0:0-5.git85ceabc.el7 | Fixed | RHSA-2019:2769 |
| Red Hat OpenShift Container Platform 3.9 | hawkular-openshift-agent-0:1.2.2-3.el7 | Fixed | RHSA-2019:2769 |
| Red Hat OpenShift Container Platform 3.9 | heapster-0:1.3.0-4.el7 | Fixed | RHSA-2019:2769 |
| Red Hat OpenShift Container Platform 3.9 | image-inspector-0:2.1.3-2.el7 | Fixed | RHSA-2019:2769 |
| Red Hat OpenShift Container Platform 3.9 | openshift-enterprise-image-registry-0:3.8.0-2.git.216.b6b90bb.el7 | Fixed | RHSA-2019:2769 |
| Red Hat OpenShift Container Platform 3.9 | openshift-eventrouter-0:0.1-3.git5bd9251.el7 | Fixed | RHSA-2019:2769 |
| Red Hat OpenShift Container Platform 3.9 | openshift-external-storage-0:0.0.1-9.git78d6339.el7 | Fixed | RHSA-2019:2769 |
| Red Hat OpenShift Container Platform 3.9 | openvswitch-ovn-kubernetes-0:0.1.0-3.el7 | Fixed | RHSA-2019:2769 |
| Red Hat OpenShift Container Platform 4.1 | openshift-0:4.1.10-201908060758.git.0.d81afa6.el7 | Fixed | RHSA-2019:2504 |
| Red Hat Storage 3 | heketi | Not affected | n/a |
k8s.io/apiextensions-apiserver
Go
Introduced 0.7.0 Fixed 0.13.9k8s.io/apiextensions-apiserver
Go
Introduced 0.14.0 Fixed 0.14.5k8s.io/apiextensions-apiserver
Go
Introduced 0.15.0 Fixed 0.15.2
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| Go | k8s.io/apiextensions-apiserver | 0.7.0 | 0.13.9 |
| Go | k8s.io/apiextensions-apiserver | 0.14.0 | 0.14.5 |
| Go | k8s.io/apiextensions-apiserver | 0.15.0 | 0.15.2 |
Remediation
Vendor solution
To mitigate, remove authorization rules that grant access to cluster-scoped resources within namespaces. For example, RBAC roles and clusterroles intended to be referenced by namespaced rolebindings should not grant access to resources:[*], apiGroups:[*], or grant access to cluster-scoped custom resources.
References (18)
- https://access.redhat.com/errata/RHBA-2019:2816 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHBA-2019:2824 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2690 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2769 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2019-11247 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1732192 Issue Tracking
- https://github.com/advisories/GHSA-fp37-c92q-4pwq Advisory
- https://github.com/kubernetes/apiextensions-apiserver/commit/b9b7d2b3f32f8edbeb47b8726710eeb868bce196
- https://github.com/kubernetes/kubernetes/issues/80983 x_refsource_CONFIRMThird Party Advisory
- https://github.com/kubernetes/kubernetes/pull/80750
- https://github.com/kubernetes/kubernetes/pull/80850
- https://github.com/kubernetes/kubernetes/pull/80851
- https://github.com/kubernetes/kubernetes/pull/80852
- https://groups.google.com/d/msg/kubernetes-security-announce/vUtEcSEY6SM/v2ZZxsmtFQAJ mailing-listx_refsource_MLISTThird Party Advisory
- https://groups.google.com/forum/#!topic/kubernetes-security-discuss/Vf31dXp0EJc
- https://nvd.nist.gov/vuln/detail/CVE-2019-11247
- https://security.netapp.com/advisory/ntap-20190919-0003/ x_refsource_CONFIRMThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2019-11247
Change history (0)
No recorded changes yet.