Description
A flaw was found in the fabric8 kubernetes-client in version 4.2.0 and after. This flaw allows a malicious pod/container to cause applications using the fabric8 kubernetes-client `copy` command to extract files outside the working path. The highest threat from this vulnerability is to integrity and system availability. This has been fixed in kubernetes-client-4.13.2 kubernetes-client-5.0.2 kubernetes-client-4.11.2 kubernetes-client-4.7.2
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-4447 | A flaw was found in the fabric8 kubernetes-client in version 4.2.0 and after. This flaw allows a malicious pod/container to cause applications using the fabric8 kubernetes-client `copy` command to extract files outside the working path. The highest threat from this vulnerability is to integrity and system availability. This has been fixed in kubernetes-client-4.13.2 kubernetes-client-5.0.2 kubernetes-client-4.11.2 kubernetes-client-4.7.2 |
Github GHSA |
GHSA-jwh2-ffg4-48xc | Improper Limitation of a Pathname to a Restricted Directory in Fabric8 Kubernetes Client |
References
History
No history.
Subscriptions
Redhat
Subscribe
A-mq Online
Subscribe
Amq Online
Subscribe
Build Of Quarkus
Subscribe
Camel Quarkus
Subscribe
Codeready Studio
Subscribe
Descision Manager
Subscribe
Integration
Subscribe
Integration Camel K
Subscribe
Jboss Enterprise Bpms Platform
Subscribe
Jboss Enterprise Brms Platform
Subscribe
Jboss Fuse
Subscribe
Kubernetes-client
Subscribe
Openshift
Subscribe
Openshift Application Runtimes
Subscribe
Openshift Container Platform
Subscribe
Process Automation
Subscribe
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-03T17:30:07.581Z
Reserved: 2020-12-17T00:00:00.000Z
Link: CVE-2021-20218
No data.
Status : Modified
Published: 2021-03-16T21:15:10.930
Modified: 2024-11-21T05:46:09.140
Link: CVE-2021-20218
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA