Home / Companies / Snyk / Blog / Post Details
Content Deep Dive

How to Detect and Remediate Kubernetes Vulnerability CVE-2019-11249

Blog post from Snyk

Post Details
Company
Date Published
Author
Hayley Denbraver
Word Count
884
Company Posts That Month
18
Language
English
Hacker News Points
-
Post removed?
No
Summary

Kubernetes has recently experienced two serious vulnerabilities, CVE-2019-11247 and CVE-2019-11249, which can be exploited for directory traversal attacks and bypassing security permissions through role-based access control. These issues arise from insufficient security configurations, such as incorrect or missing path sanitization in the kubectl cp operation, allowing malicious actors to manipulate file systems outside their intended scope. To remediate these vulnerabilities, users are advised to upgrade to a patched version of Kubernetes, remove wildcard role definitions for resources or apiGroups if upgrading is not possible, and avoid removing Role-Based Access Control (RBAC) from clusters, as this would introduce an even larger security risk. By taking these steps, users can protect their Kubernetes clusters from these serious vulnerabilities.

Trends Found in this Post
Trend Post Mentions Total Month Mentions Posts Companies MoM
Kubernetes 12 858 102 34 +23%
Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.