CVE-2017-1002102: Kubernetes

Medium severity, CVSS 5.6. EPSS: 1.1% chance of exploitation in the next 30 days.

In Kubernetes versions 1.3.x, 1.4.x, 1.5.x, 1.6.x and prior to versions 1.7.14, 1.8.9 and 1.9.4 containers using a secret, configMap, projected or downwardAPI volume can trigger deletion of arbitrary files/directories from the nodes where they are running.

Affected products

  • Kubernetes Kubernetes: from 1.3.0, up to and including 1.3.10; from 1.4.0, up to and including 1.4.12; from 1.5.0, up to and including 1.5.8; from 1.6.0, up to and including 1.6.13; from 1.7.0, before 1.7.14 (fixed in 1.7.14); from 1.8.0, before 1.8.9 (fixed in 1.8.9); …

Published 2018-03-13. Last modified 2026-06-17.