World Writable Files Affecting github.com/kubernetes/client-go/discovery/cached/disk package, versions >=1.8.0 <1.12.9
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.Test your applications
25 Apr 2019
22 Apr 2019
How to fix?
github.com/kubernetes/client-go/discovery/cached/disk to version 1.12.9 or higher.
github.com/kubernetes/client-go/discovery/cached/disk is a Go clients for talking to a kubernetes cluster.
Affected versions of this package are vulnerable to World Writable Files. When using the cached location specified by the
--cache-dir option, all cache files written to this directory are written with world-writeable (
rw-rw-rw-) permissions. The default location of this directory is