IBM Support

Red Hat OpenShift on IBM Cloud is not affected by Kubernetes kubectl cp directory traversal via symlink vulnerability (CVE-2019-11251)

Created by Sharon Singer on
Published URL:
https://www.ibm.com/support/pages/node/1138000
1138000

Security Bulletin


Summary

Red Hat OpenShift on IBM Cloud is not affected by Kubernetes 'kubectl cp' directory traversal via symlink vulnerability (CVE-2019-11251)

Vulnerability Details

CVE-ID: CVE-2019-11251
Description: A vulnerability has been discovered in kubectl cp that allows a combination of two symlinks to copy a file outside of its destination directory. This could be used to allow an attacker to place a netfarious file using a symlink, outside of the destination tree.
The details for this vulnerability are very similar to CVE-2019-1002101 and CVE-2019-11246.
CVSS Base Score: 5.9
CVSS Temporal Score: https://exchange.xforce.ibmcloud.com/vulnerabilities/168617 for more information
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N)

Remediation/Fixes

While Red Hat OpenShift on IBM Cloud service itself is NOT vulnerable to CVE-2019-11251, customers are advised to ensure their kubectl and oc client binaries are updated to the latest available version based on their cluster version. For more information, see Installing the OpenShift CLI.
To verify your oc client binaries are no longer exposed, use the following command to confirm the currently running versions are 3.11.154 or later:
oc version | grep oc
To verify your kubectl client binaries are no longer exposed, use the following command to confirm the currently running versions are 1.13.11 or later:
kubectl version --client

Monitor IBM Cloud Status for Future Security Bulletins

Monitor the security notifications on the IBM Cloud Status page to be advised of future security bulletins.

References

Off

*The CVSS Environment Score is customer environment specific and will ultimately impact the Overall CVSS Score. Customers can evaluate the impact of this vulnerability in their environments by accessing the links in the Reference section of this Security Bulletin.

Disclaimer

Review the IBM security bulletin disclaimer and definitions regarding your responsibilities for assessing potential impact of security vulnerabilities to your environment.

[{"Business Unit":{"code":"BU059","label":"IBM Software w\/o TPS"},"Product":{"code":"SSJTBP","label":"IBM Cloud Kubernetes Service and Red Hat OpenShift on IBM Cloud"},"Component":"--","Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"All Versions","Edition":"","Line of Business":{"code":"LOB21","label":"Public Cloud Platform"}}]

Document Information

Modified date:
18 December 2019

UID

ibm11138000