Vulnerability Description
Privilege escalation vulnerability in MicroK8s allows a low privilege user with local access to obtain root access to the host by provisioning a privileged container. Fixed in MicroK8s 1.15.3.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Canonical | Microk8S | < 1.15.3 |
Related Weaknesses (CWE)
References
- https://discuss.kubernetes.io/t/explicit-use-of-sudo-in-microk8s-cli/7605Third Party Advisory
- https://github.com/ubuntu/microk8s/pull/590Third Party Advisory
- https://people.canonical.com/~ubuntu-security/cve/2019/CVE-2019-15789.htmlVendor Advisory
- https://pulsesecurity.co.nz/advisories/microk8s-privilege-escalationExploitThird Party Advisory
- https://discuss.kubernetes.io/t/explicit-use-of-sudo-in-microk8s-cli/7605Third Party Advisory
- https://github.com/ubuntu/microk8s/pull/590Third Party Advisory
- https://people.canonical.com/~ubuntu-security/cve/2019/CVE-2019-15789.htmlVendor Advisory
- https://pulsesecurity.co.nz/advisories/microk8s-privilege-escalationExploitThird Party Advisory
FAQ
What is CVE-2019-15789?
CVE-2019-15789 is a vulnerability with a CVSS score of 8.8 (HIGH). Privilege escalation vulnerability in MicroK8s allows a low privilege user with local access to obtain root access to the host by provisioning a privileged container. Fixed in MicroK8s 1.15.3.
How severe is CVE-2019-15789?
CVE-2019-15789 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-15789?
Check the references section above for vendor advisories and patch information. Affected products include: Canonical Microk8S.