{"id":"CVE-2019-11251","aliases":["GHSA-6qfg-8799-r575","GO-2022-0802"],"url":"https://o3.security/vulnerability/CVE-2019-11251","summary":"Kubernetes kubectl cp Vulnerable to Symlink Attack","details":"The Kubernetes kubectl cp command in versions 1.1-1.12, and versions prior to 1.13.11, 1.14.7, and 1.15.4 allows a combination of two symlinks provided by tar output of a malicious container to place a file outside of the destination directory specified in the kubectl cp invocation. This could be used to allow an attacker to place a nefarious file using a symlink, outside of the destination tree.","published":"2020-02-03T16:15:11.140Z","modified":"2026-08-07T11:48:03.130669530Z","cvss":{"score":5.7,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"Go","name":"k8s.io/kubernetes","fixedVersion":"1.13.11"},{"ecosystem":"Go","name":"k8s.io/kubernetes","fixedVersion":"1.14.7"},{"ecosystem":"Go","name":"k8s.io/kubernetes","fixedVersion":"1.16.0"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://github.com/kubernetes/kubernetes/issues/87773"},{"type":"ADVISORY","url":"https://groups.google.com/d/msg/kubernetes-announce/YYtEFdFimZ4/nZnOezZuBgAJ"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-07T11:48:03.130669530Z"}}