106493vdb entry
http://www.securityfocus.com/bid/106493 CVE-2018-18264
HIGHNuclei
Kubernetes Dashboard <1.10.1 - Authentication Bypass
Record summary
CVE-2018-18264 has a selected CVSS score of 7.5 (high); EIP currently links 1 Nuclei template.
Description
Kubernetes Dashboard before 1.10.1 allows attackers to bypass authentication and use Dashboard's Service Account for reading secrets within the cluster.
Description source: CVE List
Exploitation context
Available material
- Nuclei templates
- 1
Nuclei templates
1ProjectDiscoveryHIGHKubernetes Dashboard <1.10.1 - Authentication BypassCVSS 7.5
Kubernetes Dashboard before 1.10.1 allows attackers to bypass authentication and use Dashboard's Service Account for reading secrets within the cluster.
Impact
An attacker can bypass authentication and gain unauthorized access to the Kubernetes Dashboard, potentially leading to further compromise of the Kubernetes cluster.
Remediation
Upgrade to Kubernetes Dashboard version 1.10.1 or later to mitigate the authentication bypass vulnerability.
WeaknessesCWE-306
Authorsedoardottt
Template tagscvecve2018kubernetesk8sauth-bypassvuln
CVSS vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CPE: cpe:2.3:a:kubernetes:dashboard:*:*:*:*:*:*:*:*
Shodan: product:"Kubernetes"
Shodan: product:"kubernetes"
https://github.com/kubernetes/dashboard/pull/3289 https://sysdig.com/blog/privilege-escalation-kubernetes-dashboard/ https://groups.google.com/forum/#!topic/kubernetes-announce/yBrFf5nmvfI https://nvd.nist.gov/vuln/detail/CVE-2018-18264 https://github.com/kubernetes/dashboard/pull/3400
Source: ProjectDiscovery
References
7github.com
https://github.com/kubernetes/dashboard/pull/3289 github.com
https://github.com/kubernetes/dashboard/pull/3400 github.com
https://github.com/kubernetes/dashboard/releases/tag/v1.10.1 groups.google.com
https://groups.google.com/forum nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2018-18264 sysdig.com
https://sysdig.com/blog/privilege-escalation-kubernetes-dashboard