Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-cghx-9gcr-r42x

Опубликовано: 29 янв. 2021
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

Path Traversal in the Java Kubernetes Client

Kubernetes Java client libraries in version 10.0.0 and versions prior to 9.0.1 allow writes to paths outside of the current directory when copying multiple files from a remote pod which sends a maliciously crafted archive. This can potentially overwrite any files on the system of the process executing the client code.

Пакеты

Наименование

io.kubernetes:client-java

maven
Затронутые версииВерсия исправления

< 9.0.2

9.0.2

Наименование

io.kubernetes:client-java

maven
Затронутые версииВерсия исправления

= 10.0.0

10.0.1

EPSS

Процентиль: 78%
0.01085
Низкий

7.5 High

CVSS3

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 7.4
redhat
около 5 лет назад

Kubernetes Java client libraries in version 10.0.0 and versions prior to 9.0.1 allow writes to paths outside of the current directory when copying multiple files from a remote pod which sends a maliciously crafted archive. This can potentially overwrite any files on the system of the process executing the client code.

CVSS3: 9.1
nvd
около 5 лет назад

Kubernetes Java client libraries in version 10.0.0 and versions prior to 9.0.1 allow writes to paths outside of the current directory when copying multiple files from a remote pod which sends a maliciously crafted archive. This can potentially overwrite any files on the system of the process executing the client code.

EPSS

Процентиль: 78%
0.01085
Низкий

7.5 High

CVSS3

Дефекты

CWE-22