V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsProductsVendorsDocs
CVE-2016-1905
DEB
High

The API server in Kubernetes does not properly check admission control, which allows remote authenticated users to access additional resour…

CVSS
7.7
High
EPSS
0.02
p72
Published
2016-01-01
Updated
2016-01-01
Description

The API server in Kubernetes does not properly check admission control, which allows remote authenticated users to access additional resources via a crafted patched object.

Tags · CWE
CWE-284
CWE-285
CAPEC-1
CAPEC-5
CAPEC-13
CAPEC-17
CAPEC-19
CAPEC-39
CAPEC-45
CAPEC-51
CAPEC-59
CAPEC-60
CAPEC-76
CAPEC-77
CAPEC-87
CAPEC-104
CAPEC-127
CAPEC-402
CAPEC-441
CAPEC-478
CAPEC-479
CAPEC-502
CAPEC-503
CAPEC-536
CAPEC-546
CAPEC-550
CAPEC-551
CAPEC-552
CAPEC-556
CAPEC-558
CAPEC-562
CAPEC-563
CAPEC-564
CAPEC-578
CAPEC-647
CAPEC-668
Affected products
Atomic-openshiftHeapsterJenkinsKubernetesNodejs-align-textNodejs-ansi-greenNodejs-ansi-wrapNodejs-anymatchNodejs-arr-diffNodejs-arr-flattenNodejs-array-uniqueNodejs-arrifyNodejs-async-eachNodejs-binary-extensionsNodejs-bracesNodejs-capture-stack-traceNodejs-chokidarNodejs-configstoreNodejs-create-error-classNodejs-deep-extend
CVSS vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N
Timeline
2016-01-01
Published
2016-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: L
Low (L)
Privileges Required
PR: L
Low (L)
User Interaction
UI: N
None (N)
Scope
S: C
Changed (C)
Confidentiality Impact
C: N
None (N)
Integrity Impact
I: H
High (H)
Availability Impact
A: N
None (N)
Exploit indicators
EPSS
0.016 · p72
Known exploited (KEV)
No
MITRE ATT&CK
Inferred via CAPEC
└ via CAPEC-647 · CWE-285
└ via CAPEC-647 · CWE-285
└ via CAPEC-552 · CWE-284
└ via CAPEC-19 · CWE-284
└ via CAPEC-564 · CWE-284
└ via CAPEC-562 · CWE-284
└ via CAPEC-127 · CWE-285
└ via CAPEC-60 · CWE-285
└ via CAPEC-558 · CWE-284
└ via CAPEC-552 · CWE-284
└ via CAPEC-550 · CWE-284
└ via CAPEC-564 · CWE-284
└ via CAPEC-478 · CWE-284
└ via CAPEC-564 · CWE-284
└ via CAPEC-556 · CWE-284
└ via CAPEC-558 · CWE-284
└ via CAPEC-19 · CWE-284
└ via CAPEC-564 · CWE-284
└ via CAPEC-552 · CWE-284
└ via CAPEC-60 · CWE-285
└ via CAPEC-647 · CWE-285
└ via CAPEC-479 · CWE-284
└ via CAPEC-578 · CWE-284
└ via CAPEC-668 · CWE-285
└ via CAPEC-13 · CWE-285
Known exploits — Сканер-ВС
No Сканер-ВС checks registered for this vulnerability yet.
Affected products
ProductVendorStatus
atomic-openshiftTracked
heapsterTracked
jenkinsTracked
kubernetesTracked
nodejs-align-textTracked
nodejs-ansi-greenTracked
nodejs-ansi-wrapTracked
nodejs-anymatchTracked
nodejs-arr-diffTracked
nodejs-arr-flattenTracked
nodejs-array-uniqueTracked
nodejs-arrifyTracked
nodejs-async-eachTracked
nodejs-binary-extensionsTracked
nodejs-bracesTracked
nodejs-capture-stack-traceTracked
nodejs-chokidarTracked
nodejs-configstoreTracked
nodejs-create-error-classTracked
nodejs-deep-extendTracked
Showing first 20 of 120
Source databases
DEB
CVE
RED
Related vulnerabilities