CVE-2018-1002102: Fedoraproject Fedora
Low severity, CVSS 2.6. EPSS: 0.6% chance of exploitation in the next 30 days.
Improper validation of URL redirection in the Kubernetes API server in versions prior to v1.14.0 allows an attacker-controlled Kubelet to redirect API server requests from streaming endpoints to arbitrary hosts. Impacted API servers will follow the redirect as a GET request with client-certificate credentials for authenticating to the Kubelet.
Affected products
- Fedoraproject Fedora: version 31 only
- Kubernetes Kubernetes: from 1.10.0, up to and including 1.13.13; version 1.14.0 only
Published 2019-12-05. Last modified 2026-06-17.