CVE-2019-11245
MEDIUM4.9EPSS 0.15%Kubelet Incorrect Privilege Assignment in k8s.io/kubernetes
Published: 4/24/2024Modified: 3/3/2026
Description
Kubelet Incorrect Privilege Assignment in k8s.io/kubernetes
Affected packages (2)
- Go/k8s.io/kubernetes>= 1.13.0, < 1.13.7, >= 1.14.0, < 1.14.3
- Go/k8s.io/kubernetes/cmd/kubelet>= 1.14.0, < 1.14.3
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM4.9 | CVSS:3.0/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L |
References (9)
- ADVISORYhttps://github.com/advisories/GHSA-r76g-g87f-vw8f
- ADVISORYhttps://nvd.nist.gov/vuln/detail/CVE-2019-11245
- PATCHhttps://github.com/kubernetes/kubernetes
- WEBhttps://bugzilla.redhat.com/show_bug.cgi?id=1715726
- WEBhttps://github.com/kubernetes/kubernetes/issues/78308
- WEBhttps://github.com/kubernetes/kubernetes/pull/76665
- WEBhttps://github.com/kubernetes/kubernetes/pull/76665/commits/26e3c8674e66f0d10170d34f5445f0aed207387f
- WEBhttps://pkg.go.dev/vuln/GO-2024-2780
- WEBhttps://security.netapp.com/advisory/ntap-20190919-0003