CVE-2018-1002102: Fedoraproject Fedora

Low severity, CVSS 2.6. EPSS: 0.6% chance of exploitation in the next 30 days.

Improper validation of URL redirection in the Kubernetes API server in versions prior to v1.14.0 allows an attacker-controlled Kubelet to redirect API server requests from streaming endpoints to arbitrary hosts. Impacted API servers will follow the redirect as a GET request with client-certificate credentials for authenticating to the Kubelet.

Affected products

  • Fedoraproject Fedora: version 31 only
  • Kubernetes Kubernetes: from 1.10.0, up to and including 1.13.13; version 1.14.0 only

Published 2019-12-05. Last modified 2026-06-17.