Oval Definition:oval:org.opensuse.security:def:20181002105
Revision Date:2022-06-30Version:1
Title:CVE-2018-1002105
Description:

In all Kubernetes versions prior to v1.10.11, v1.11.5, and v1.12.3, incorrect handling of error responses to proxied upgrade requests in the kube-apiserver allowed specially crafted requests to establish a connection through the Kubernetes API server to backend servers, then send arbitrary requests over the same connection directly to the backend, authenticated with the Kubernetes API server's TLS credentials used to establish the backend connection.
Family:unixClass:vulnerability
Status:Reference(s):CVE-2018-1002105
SUSE-SU-2018:4020-1
openSUSE-SU-2020:0554-1
Mitre CVE-2018-1002105
SUSE CVE-2018-1002105
SUSE-SU-2018:4020-1
openSUSE-SU-2020:0554-1
Platform(s):openSUSE Leap 15.1
openSUSE Tumbleweed
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Module for Public Cloud 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server 12 SP3
SUSE Linux Enterprise Server 12 SP4
SUSE Linux Enterprise Server 12 SP5
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Server for SAP Applications 12 SP3
SUSE Linux Enterprise Server for SAP Applications 12 SP4
SUSE Linux Enterprise Server for SAP Applications 12 SP5
SUSE Manager Proxy 4.0
SUSE Manager Retail Branch Server 4.0
SUSE Manager Server 4.0
Product(s):
Definition Synopsis
  • openSUSE Leap 15.1 is installed
  • AND Package Information
  • cri-o-1.17.1-lp151.2 is installed
  • AND cri-o is signed with openSUSE key
  • OR
  • cri-o-kubeadm-criconfig-1.17.1-lp151.2 is installed
  • AND cri-o-kubeadm-criconfig is signed with openSUSE key
  • OR
  • cri-tools-1.18.0-lp151.2 is installed
  • AND cri-tools is signed with openSUSE key
  • OR
  • go1.14-1.14-lp151.6 is installed
  • AND go1.14 is signed with openSUSE key
  • OR
  • go1.14-doc-1.14-lp151.6 is installed
  • AND go1.14-doc is signed with openSUSE key
  • OR
  • go1.14-race-1.14-lp151.6 is installed
  • AND go1.14-race is signed with openSUSE key
  • OR
  • kubernetes-1.18.0-lp151.5 is installed
  • AND kubernetes is signed with openSUSE key
  • OR
  • kubernetes-apiserver-1.18.0-lp151.5 is installed
  • AND kubernetes-apiserver is signed with openSUSE key
  • OR
  • kubernetes-client-1.18.0-lp151.5 is installed
  • AND kubernetes-client is signed with openSUSE key
  • OR
  • kubernetes-controller-manager-1.18.0-lp151.5 is installed
  • AND kubernetes-controller-manager is signed with openSUSE key
  • OR
  • kubernetes-kubeadm-1.18.0-lp151.5 is installed
  • AND kubernetes-kubeadm is signed with openSUSE key
  • OR
  • kubernetes-kubelet-common-1.18.0-lp151.5 is installed
  • AND kubernetes-kubelet-common is signed with openSUSE key
  • OR
  • kubernetes-kubelet1.17-1.18.0-lp151.5 is installed
  • AND kubernetes-kubelet1.17 is signed with openSUSE key
  • OR
  • kubernetes-kubelet1.18-1.18.0-lp151.5 is installed
  • AND kubernetes-kubelet1.18 is signed with openSUSE key
  • OR
  • kubernetes-master-1.18.0-lp151.5 is installed
  • AND kubernetes-master is signed with openSUSE key
  • OR
  • kubernetes-node-1.18.0-lp151.5 is installed
  • AND kubernetes-node is signed with openSUSE key
  • OR
  • kubernetes-proxy-1.18.0-lp151.5 is installed
  • AND kubernetes-proxy is signed with openSUSE key
  • OR
  • kubernetes-scheduler-1.18.0-lp151.5 is installed
  • AND kubernetes-scheduler is signed with openSUSE key
  • Definition Synopsis
  • openSUSE Tumbleweed is installed
  • AND Package Information
  • kubernetes-apiserver-1.22.2-21.2 is installed
  • OR kubernetes-apiserver-minus1-1.21.5-21.2 is installed
  • OR kubernetes-client-1.22.2-21.2 is installed
  • OR kubernetes-controller-manager-1.22.2-21.2 is installed
  • OR kubernetes-controller-manager-minus1-1.21.5-21.2 is installed
  • OR kubernetes-coredns-1.8.4-21.2 is installed
  • OR kubernetes-coredns-minus1-1.8.0-21.2 is installed
  • OR kubernetes-etcd-3.5.0-21.2 is installed
  • OR kubernetes-etcd-minus1-3.4.13-21.2 is installed
  • OR kubernetes-kubeadm-1.22.2-21.2 is installed
  • OR kubernetes-kubelet-1.22.2-21.2 is installed
  • OR kubernetes-proxy-1.22.2-21.2 is installed
  • OR kubernetes-proxy-minus1-1.21.5-21.2 is installed
  • OR kubernetes-scheduler-1.22.2-21.2 is installed
  • OR kubernetes-scheduler-minus1-1.21.5-21.2 is installed
  • Definition Synopsis
  • Release Information
  • SUSE Linux Enterprise High Performance Computing 12 is installed
  • OR SUSE Linux Enterprise Module for Public Cloud 12 is installed
  • OR SUSE Linux Enterprise Server 12 is installed
  • OR SUSE Linux Enterprise Server 12 SP3 is installed
  • OR SUSE Linux Enterprise Server 12 SP4 is installed
  • OR SUSE Linux Enterprise Server 12 SP5 is installed
  • OR SUSE Linux Enterprise Server for SAP Applications 12 is installed
  • OR SUSE Linux Enterprise Server for SAP Applications 12 SP3 is installed
  • OR SUSE Linux Enterprise Server for SAP Applications 12 SP4 is installed
  • OR SUSE Linux Enterprise Server for SAP Applications 12 SP5 is installed
  • AND kubernetes-client is not affected
  • Definition Synopsis
  • Release Information
  • SUSE Manager Proxy 4.0 is installed
  • OR SUSE Manager Retail Branch Server 4.0 is installed
  • OR SUSE Manager Server 4.0 is installed
  • AND kubernetes is affected
  • BACK