Kubernetes Dashboard Vulnerability in Minikube by Kubernetes
CVE-2018-1002103

8.1HIGH

Key Information:

Vendor
Kubernetes
Status
Vendor
CVE Published:
3 October 2022

Summary

Minikube versions 0.3.0 to 0.29.0 exhibit a vulnerability where the Kubernetes Dashboard is exposed on the VM's IP address at port 30000. In environments where the VM's IP can be easily predicted, attackers may exploit this exposure using DNS rebinding techniques to indirectly access the dashboard. This can lead to unauthorized creation of Kubernetes Deployments that run arbitrary code. Additionally, if the Minikube mount feature is utilized, attackers could potentially gain direct access to the host filesystem.

Affected Version(s)

Minikube v0.3.0

Minikube < unspecified

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Reported by Alex Kaskasoli
.