<p>Patches are available for a critical privilege escalation flaw (CVE-2018-1002105) in the open-source container orchestration system, Kubernetes.</p>
<h2>Background</h2>
<p>On December 3, details about a privilege escalation vulnerability in Kubernetes, the popular open source container orchestration system, <a href="https://github.com/kubernetes/kubernetes/issues/71411">were publicly disclosed by the Kubernetes team</a>. Kubernetes is used to automate the deployment, scaling, and management of containerized applications.</p>
<h2>Vulnerability details</h2>
<p>Designated as CVE-2018-1002105, the vulnerability exists in the proxy handling function of the Kubernetes API server. Arbitrary requests can be made to the backend server via the Kubernetes API server if the requestor is permitted to establish a connection to the API server. According to the Kubernetes team, “all users (authenticated and unauthenticated) are allowed to perform discovery API calls that allow this escalation” through the default configuration.</p>
<p>Additionally, this vulnerability allows for the escalation of Kubernetes pod API requests (exec, attach, portforward) through the kubelet API.</p>
<p>The Kubernetes team notes that, due to the fact that “unauthorized requests are made over an established connection,” the requests won’t appear in the audit or server logs. However, the requests appearing in either the kubelet or aggregated API server logs will be “indistinguishable from correctly authorized and proxied requests via the Kubernetes API server,” making it difficult to detect the use of this vulnerability in your environment.</p>
<h2>Urgently required actions</h2>
<p>System administrators, users or anyone deploying Kubernetes should upgrade to the patched versions immediately. The following versions of Kubernetes are affected by this vulnerability:</p>
<ul><li>Kubernetes v1.0.x-1.9.x</li>
<li>Kubernetes v1.10.0-1.10.10</li>
<li>Kubernetes v1.11.0-1.11.4</li>
<li>Kubernetes v1.12.0-1.12.2</li></ul>
<p>The vulnerability is addressed in the following versions of Kubernetes:</p>
<ul><li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG-1.10.md/#... v1.10.11</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG-1.11.md/#... v1.11.5</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG-1.12.md/#... v1.12.3</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG-1.13.md/#... v1.13.0-rc.1</a></li></ul>
<p>Additionally, users of Red Hat’s OpenShift Container Platform should upgrade to the <a href="https://access.redhat.com/security/cve/cve-2018-1002105">patched versions</a> as soon as possible.</p>
<p>Lastly, please review the security tracker pages for <a href="https://security-tracker.debian.org/tracker/CVE-2018-1002105">Debian</a> and <a href="https://www.suse.com/security/cve/CVE-2018-1002105/">SUSE</a> distributions for up-to-date information on the availability of a Kubernetes patch on these platforms.</p>
<h2>Identifying affected systems</h2>
<p>A list of Nessus plugins to identify this vulnerability will appear <a href="https://www.tenable.com/plugins/search?q=cves%3A(%22CVE-2018-1002105%22)&sort=&page=1">here</a> as they’re released.</p>
<h2>Get more information</h2>
<ul><li><a href="https://github.com/kubernetes/kubernetes/issues/71411">Kubernetes: proxy request handling in kube-apiserver can leave vulnerable TCP connections</a></li>
<li><a href="https://access.redhat.com/security/cve/cve-2018-1002105">Red Hat: About CVE-2018-1002105</a></li>
<li><a href="https://security-tracker.debian.org/tracker/CVE-2018-1002105">Debian Security Tracker: CVE-2018-1002105</a></li>
<li><a href="https://www.suse.com/security/cve/CVE-2018-1002105/">SUSE Security Tracker: CVE-2018-1002105</a></li></ul>
<p><b><i>Learn more about <a href="https://www.tenable.com/products">Tenable</a>, the first Cyber Exposure platform for holistic management of your modern attack surface. Get a <a href="https://www.tenable.com/products/tenable-io/vulnerability-management/eva... 60-day trial</a> of Tenable.io Vulnerability Management. </i></b></p>