Security readout for executives and security teams
Plain-English summary
This flaw lets a malicious or compromised container influence what happens when an operator uses kubectl cp to copy files from that container. Instead of only placing files in the requested destination, a malicious tar response could write files elsewhere on the operator’s machine, within that user’s permissions.
Executive priority
Treat this as a targeted operator-workstation integrity risk, not a broad remote compromise. Prioritize patching kubectl wherever privileged staff or automation interact with clusters, especially in environments where containers may be supplied by customers, tenants, or less-trusted teams.
Technical view
kubectl cp invokes tar inside the container, transfers the archive, then unpacks it locally. If the container’s tar binary is malicious, it can produce archive entries that abuse symlink directory traversal and cause local arbitrary file writes. Affected Kubernetes versions include releases before 1.13.9, 1.14.5, and 1.15.2, plus older listed branches.
Likely exposure
Exposure is most likely for administrators, developers, or automation using affected kubectl versions to copy files from untrusted, compromised, or attacker-controlled containers. Servers are not passively exploitable; the attack depends on kubectl cp being run by a user with cluster access.
Exploitation context
The source bundle does not show CISA KEV listing or confirmed active exploitation. Exploitation requires low privileges in the Kubernetes context and user interaction: someone must run kubectl cp against a container whose tar behavior is malicious or controlled by an attacker.
Researcher notes
The key control boundary is the local kubectl client unpacking archive output generated inside the container. Validation should focus on client versions and kubectl cp usage paths. Do not assume passive cluster exposure; the described attack path depends on malicious container-side tar output and a user-initiated copy operation.
Mitigation direction
- Upgrade affected Kubernetes/kubectl versions to 1.13.9, 1.14.5, 1.15.2, or later fixed vendor releases.
- Apply relevant vendor updates from Red Hat, NetApp, or platform providers where Kubernetes is packaged.
- Restrict kubectl cp use against untrusted or compromised containers until client tooling is patched.
- Review operational guidance from Kubernetes and your Kubernetes distribution before defining compensating controls.
Validation and detection
- Inventory kubectl versions used by administrators, CI jobs, and support automation.
- Confirm affected versions are no longer in use on workstations and build runners.
- Identify workflows that copy files from containers using kubectl cp.
- Review recent kubectl cp use involving suspicious, untrusted, or compromised containers.
- Verify vendor advisories applicable to your Kubernetes distribution are applied.
Public sources used
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
CWE-61: Exact CWE lookup
Use the exact CWE identifier as the starting point before reviewing related ATT&CK behavior. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.
Open ATT&CK lookupFile access behavior lookup
The CVE wording references file access or upload behavior, so file telemetry and web shell review may help. This is a Glexia inferred lookup path, not an official MITRE, ATT&CK, or CVE Program mapping.
Open ATT&CK lookupContainer behavior lookup
The affected technology mentions containers, so container-specific ATT&CK technique review may help. This is a Glexia inferred lookup path, not an official MITRE, ATT&CK, or CVE Program mapping.
Open ATT&CK lookupCVE-2019-11249 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
Open ATT&CK lookup- Severity
- Medium
- CVSS
- 4.8 (3.0)
- Known Exploited
- No
- Published
Vector: CVSS:3.0/AV:N/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:N
CNA and ADP enrichment extracted from CVE v5
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
CVSS vector scores
1 official scoreWe collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.
CVSS:3.0/AV:N/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:N1.23.6Primary CVE scoreVulnerability scoring details
Base CVSS 3.0 score
4.8MediumVector: CVSS:3.0/AV:N/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:N
Source materials
- CVE List V5 sourceCVE List V5
- v1.13.9, v1.14.5, v1.15.2 released to address CVE-2019-11247, CVE-2019-11249CVE reference · mailing-list, x_refsource_MLIST
- https://github.com/kubernetes/kubernetes/issues/80984CVE reference · x_refsource_CONFIRM
- https://security.netapp.com/advisory/ntap-20190919-0003/CVE reference · x_refsource_CONFIRM
- RHBA-2019:2816CVE reference · vendor-advisory, x_refsource_REDHAT
- RHBA-2019:2794CVE reference · vendor-advisory, x_refsource_REDHAT
- RHBA-2019:2824CVE reference · vendor-advisory, x_refsource_REDHAT
- RHSA-2019:3239CVE reference · vendor-advisory, x_refsource_REDHAT
- RHSA-2019:3811CVE reference · vendor-advisory, x_refsource_REDHAT
Products and packages named in the record
CWE details
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
UNIX Symbolic Link (Symlink) Following
UNIX Symbolic Link (Symlink) Following represents a recurring weakness pattern that can create exploitable paths when design, validation, or implementation controls are missing.
