Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
cve-2018-1002105 — Kubernetes cluster vulnerability scanner that detects CVE-2018-1002105 by testing for unauthenticated API access and privilege escalation via malformed requests. | Kitploit
Tools/GitHubGitHub/gravitational/cve-2018-1002105
Container SecurityVulnerability AnalysisExploitationPenetration TestingCloud SecurityMisconfigurationArchived
GitHubgravitational/cve-2018-1002105

cve-2018-1002105

Kubernetes cluster vulnerability scanner that detects CVE-2018-1002105 by testing for unauthenticated API access and privilege escalation via malformed requests.

View Repository
1912547 years agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2018-1002105

Test utility that checks a cluster for the high severity kubernetes CVE published here. A stakeholder-level writeup of the CVE-2018-1002105 may be found at https://gravitational.com/blog/kubernetes-websocket-upgrade-security-vulnerability/

Warning

Running this test through layer 7 load balancers or proxies in front of you're kubernetes apiserver may be unreliable and produce incorrect results. This test operates by connecting to the apiserver, and checking for side effects of the apiserver that exhibit the bug in kubernetes. Running this proof of concept through a layer 7 load balancer, may falsely indicate that the API is vulnerable to CVE-2018-1002105

Managed Kubernetes (AKS, EKS, GKE) Note

This tool veers toward false-positives, if your Kubernetes API is provided by a major cloud provider (such as Amazon AWS EKS, Google Cloud GKE or Microsoft Azure AKS), that service provider has almost certainly already patched your apiserver and you are no longer affected by CVE-2018-1002105. We would welcome pull requests that improve the detection of non-vulnerable apiserver endpoints.

Build and Run

root@kitploit:~
go get github.com/gravitational/cve-2018-1002105
cd $GOPATH/src/github.com/gravitational/cve-2018-1002105
go run main.go

Running as a container

root@kitploit:~
docker run -it --rm -v $HOME/.kube/config:/kubeconfig: quay.io/gravitational/cve-2018-1002105:latest

Testing a cluster

The tool will attempt to test for two things, whether the cluster allows unauthenticated access to the API, which will then allow unauthenticated access to aggregate API endpoint. It will also attempt to find a pod, and attempt to test whether the apiserver will leave the connection open on a malformed request, which indicates the cluster is susceptible to CVE-2018-1002105.

root@kitploit:~
Testing for unauthenticated access...
> API allows unauthenticated access
Testing for privilege escalation...
> API is vulnerable to CVE-2018-1002105

If you see API allows unauthenticated access it indicates that the test was able to detect unauthenticated access to the cluster. This test is fairly basic, but should detect a default configuration where anonymous access to the cluster is allowed.

If you see API is vulnerable to CVE-2018-1002105, this means that using the provided kubeconfig, the tool was able to test and confirm your cluster is vulnerable.

Download Tool