SCA: security update for k8s.io/kubernetes (GHSA-2jq6-ffph-p4h8)

medium Tenable Self-Hosted Container Security Plugin ID 434291

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In Kubernetes versions 1.5.x, 1.6.x, 1.7.x, 1.8.x, and prior to version 1.9.6, the kubectl cp command
insecurely handles tar data returned from the container, and can be caused to overwrite arbitrary local
files. (CVE-2018-1002100)

See Also

https://github.com/advisories/GHSA-2jq6-ffph-p4h8

Plugin Details

Severity: Medium

ID: 434291

Version: Revision 1.3

Type: Local

Family: SCA Checks

Published: 8/19/2025

Updated: 7/2/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Low

Score: 3

Percentile: 23.18

Vendor

Vendor Severity: Medium

CVSS v2

Risk Factor: Low

Base Score: 3.6

Temporal Score: 2.7

Vector: CVSS2#AV:L/AC:L/Au:N/C:N/I:P/A:P

CVSS Score Source: CVE-2018-1002100

CVSS v3

Risk Factor: Medium

Base Score: 5.5

Temporal Score: 4.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 5/13/2022

Vulnerability Publication Date: 6/2/2018

Reference Information

CVE: CVE-2018-1002100

cwe: CWE-20